Privacy Policy

It is very important to us to handle the data of our website visitors with the utmost care and to protect it as best as possible. For this reason, we make every effort to comply with the requirements of the GDPR.

Below, we explain how we process your data on our website. We use language that is as clear and transparent as possible so that you truly understand what happens to your data.

The Data Controller

The data controller within the meaning of the GDPR is responsible for data processing on this website. This is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

You can contact the data controller at:

1. Introduction

This website is operated by: Rollgut® Einzelunternehmen.

2. General Information

2.1 Processing of personal data and other terms

Data protection applies to the processing of personal data. Personal refers to all data with which you can be personally identified. This is e.g. the IP address of the device (PC, laptop, smartphone, etc.) you are currently sitting in front of. Such data is processed when 'something happens with it'. Here, e.g., the IP is transmitted from the browser to our provider and automatically stored there. This is then a processing (according to Art. 4 No. 2 GDPR) of personal data (according to Art. 4 No. 1 GDPR).

These and other legal definitions can be found in Art. 4 GDPR.

2.2 Applicable regulations / laws – GDPR, BDSG and TDDDG

The scope of data protection is regulated by laws. In this case, these are the GDPR (General Data Protection Regulation) as a European regulation and the BDSG (Federal Data Protection Act) as a national law.

In addition, the TDDDG supplements the regulations of the GDPR, insofar as it concerns the use of cookies.

2.3 How data is generally processed on this website

As we have already established, there is data (e.g. IP address) that is collected automatically. This data is predominantly required for the technical provision of the homepage. Insofar as we use personal data beyond this or collect other data, we will inform you about it or ask for your consent.

You deliberately share other personal data with us.

You will find detailed information on this further below.

2.4 Your rights

The GDPR provides you with comprehensive rights. These include, for example, free information about the origin, recipient and purpose of your stored personal data. In addition, you can request the correction, blocking or deletion of this data or complain to the competent data protection supervisory authority. You can revoke any consent given at any time.

You will find out what these rights look like in detail and how to exercise them in the last section of this privacy policy.

2.5 Data protection – Our view

Data protection is more than just a chore for us! Personal data has a great value and mindful handling of this data should be a matter of course in our digitized world. Moreover, as a website visitor, you should be able to decide for yourself what "happens" to your data, when, and by whom. Therefore, we commit ourselves to complying with all legal provisions, collecting only the data necessary for us, and naturally treating it confidentially.

2.6 Disclosure and deletion

The disclosure and deletion of data are also important and sensitive topics. Therefore, we would like to briefly inform you in advance about our general approach to this.

Data is only passed on based on a legal basis and only when this is unavoidable. This can be the case in particular if it involves a so-called processor and a data processing agreement has been concluded in accordance with Art. 28 GDPR.

We delete your data when the purpose and the legal basis for processing no longer apply and there are no other legal obligations precluding deletion. Art. 17 GDPR also provides a 'good' overview of this.

For all further information, please refer to this privacy policy and contact the controller if you have specific questions.

2.7 Hosting

This website is hosted on our own servers. We store the personal data collected on this website on our servers. This includes, on the one hand, the automatically collected and stored log files (for more details see below), as well as all other data provided by website visitors.

The legal basis for processing is Art. 6 Para. 1 lit. a, b and f GDPR, as well as § 25 Para. 1 TDDDG, provided that consent includes the storage of cookies or access to information in the end device of the website visitor or user within the meaning of the TDDDG.

We process only such data that is necessary for the fulfillment of our performance obligations.

2.8 Legal bases

The processing of personal data always requires a legal basis. The GDPR provides the following options in Art. 6 Para. 1 Sentence 1:

  1. The data subject has given consent to the processing of his or her personal data for one or more specific purposes;
  2. Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
  3. Processing is necessary for compliance with a legal obligation to which the controller is subject;
  4. Processing is necessary in order to protect the vital interests of the data subject or of another natural person;
  5. Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  6. Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

In the following sections, we will specify the concrete legal basis for the respective processing.

3. What happens on our website

By visiting our website, we process your personal data.

To protect this data as best as possible against unauthorized interference by third parties, we use SSL or TLS encryption. You can recognize this encrypted connection by the fact that https:// or a lock symbol is displayed in the address bar of your browser.

In the following, you will find out which data is collected when you visit our website, for what purpose this is done, and on what legal basis.

3.1 Data collection when accessing the website

By accessing the website, information is automatically stored in so-called server log files. This involves the following information:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of the server request
  • IP address

This data is temporarily required to be able to display our website to you permanently and without problems. In particular, this data thereby serves the following purposes:

  • System security of the website
  • System stability of the website
  • Troubleshooting on the website
  • Establishing a connection to the website
  • Presentation of the website

The data processing takes place in accordance with Art. 6 Para. 1 lit. f GDPR and is carried out based on our legitimate interest in processing this data, in particular the interest in the functionality of the website and its security.

This data is stored pseudonymized whenever possible and deleted after achieving the respective purpose.

Insofar as the server log files enable the identification of the data subject, the data is stored for a maximum period of 14 days. An exception exists if a security-relevant event occurs. In this case, the server log files are stored until the security-relevant event is resolved and conclusively clarified.

Otherwise, a consolidation with other data does not take place.

3.2 Data processing through user input

3.2.1 Our own data collection

We offer the following (services) on our website: Newsletter, contact form, webshop orders.

For this purpose, we collect the following data:

  • Name
  • E-mail address
  • Address
  • Telephone number

The legal basis for this data processing is Art. 6 Para. 1 lit. b GDPR.

The data is deleted as soon as the respective purpose ceases to apply and it is possible according to legal requirements.

3.2.2 Contacting us

a) E-mail

If you contact us by e-mail, we process your e-mail address and, if applicable, other data contained in the e-mail. These are stored on the mail server and partially on the respective end devices. Depending on the request, the legal basis for this is regularly Art. 6 Para. 1 lit. f GDPR or Art. 6 Para. 1 lit. b GDPR. The data is deleted as soon as the respective purpose ceases to apply and it is possible according to legal requirements.

b) Telephone

If you contact us by telephone, the call data can be stored pseudonymized on the respective end device and at the telecommunications provider used. Personal data collected during the phone call is processed exclusively to handle your request. Depending on the request, the legal basis for this is regularly Art. 6 Para. 1 lit. f GDPR or Art. 6 Para. 1 lit. b GDPR. The data is deleted as soon as the respective purpose ceases to apply and it is possible according to legal requirements.

c) Contact form

3.2.3 Applications

An application is possible via our website. We process the transmitted data in order to decide on the establishment of an employment relationship.

We process name, address and contact details, information on education, qualifications and professional career as well as the submitted documents such as cover letter, CV and certificates. Further information, such as an application photo, is voluntary. The processing serves the execution of the application procedure, the assessment of suitability for the advertised position as well as communication during the procedure.

The legal basis is Art. 6 Para. 1 lit. b GDPR in conjunction with § 26 Para. 1 Sentence 1 BDSG, as the processing is necessary to decide on the establishment of an employment relationship. If special categories of personal data are processed in exceptional cases, for instance information on a severe disability, this is done on the basis of Art. 9 Para. 2 lit. b GDPR in conjunction with § 26 Para. 3 BDSG. Insofar as the processing serves to defend against asserted claims, we base it on Art. 6 Para. 1 lit. f GDPR.

Access to the application documents is granted exclusively to the internal offices involved in the procedure, in particular the HR administration and the respective specialist department. A transfer to third parties does not take place unless otherwise stated in this declaration.

If no employment takes place, the documents are deleted six months after the conclusion of the procedure. If employment takes place, the data is transferred to the personnel file. If storage of the documents beyond the conclusion of the procedure is intended for future positions, we will obtain consent beforehand. The legal basis is then Art. 6 Para. 1 lit. a GDPR. Consent can be revoked at any time with effect for the future; the lawfulness of the processing carried out until the revocation remains unaffected. Without consent, the documents will be deleted after the stated period has expired.

The transmission of the data is neither legally nor contractually required. Without this information, however, an assessment of the application is not possible. Unsolicited applications are treated according to the same principles.

3.2.4 Questionnaires/Forms

Drupal Webform

For the creation and administration of online forms such as contact, survey or registration forms, the "Drupal Webform" module is used on this website, which is provided and maintained by the open source community on Drupal.org, in particular by Jacob Rockowitz and other maintainers. The control over the collected form data lies exclusively with the website operator. Drupal Webform enables the provision of forms of any complexity, the management of submissions, the sending of notifications, uploads and dynamic form functions (e.g. conditions and multi-step processes). As part of the use of these forms, all data provided by the user in the form is processed. This includes in particular name, e-mail address, telephone number, address, free text information (e.g. message content), selection options (e.g. checkboxes, dropdowns), date/time and possibly uploaded files. The processing serves the purpose of processing the requested information, handling certain processes (e.g. feedback, registrations, applications) as well as controlling communication and organization internally. Depending on the purpose of the form, the legal basis is regularly Art. 6 Para. 1 lit. b GDPR (initiation or fulfillment of a contractual relationship) or Art. 6 Para. 1 lit. f GDPR (legitimate interest in efficient processes and communication); with specific consent also Art. 6 Para. 1 lit. a GDPR. Drupal Webform itself does not use cookies, provided that no external services (e.g. for spam protection or analysis) are integrated. A transfer of personal data to third countries by Drupal Webform does not take place. Personal data is deleted as soon as the purpose of the collection ceases to apply, a given consent is revoked or legal retention periods have expired. Further information on data protection and on individual configurations of the form can be found in the privacy policy at: https://www.drupal.org/privacy-policy

3.3 Newsletter

Simplenews (Drupal Module)

On this website, the Simplenews module is used for sending and managing newsletters. The provider and main developer of the module is think modular - digital solutions GmbH, Ebendorferstraße 3/14, 1010 Vienna, Austria. Simplenews enables the creation, management and sending of e-mail newsletters to various subscriber lists directly from the Drupal system. Both anonymous and registered persons can subscribe to newsletters, individual lists (topics/categories) can be managed, and editorial content can be sent out as a newsletter. The processed data includes in particular the e-mail address of the subscribers, the status of the newsletter registration, possibly first and last name (with appropriate configuration) as well as the status of the consent when using GDPR integrations. The processing takes place for the purpose of providing newsletter services, managing mailing lists and providing editorial or promotional information. The legal basis for the processing is generally Art. 6 Para. 1 lit. a GDPR (consent), in the case of contractual relationships Art. 6 Para. 1 lit. b GDPR. If the dispatch takes place within the framework of consent via the web form, § 25 Para. 1 TDDDG is additionally relevant. The module itself does not use cookies that go beyond the technically necessary session cookies of Drupal. Analysis, tracking or marketing cookies are not set by Simplenews. A transfer of personal data to third countries by the module itself does not take place. The data processing takes place exclusively on the website and its servers. The storage period depends on the respective processing purpose: Data is deleted as soon as the newsletter is unsubscribed, consent is revoked or the respective newsletter service is discontinued, provided that this does not conflict with any statutory retention obligations. Further information about the module can be found at: https://www.drupal.org/project/simplenews

3.4 Analysis and tracking tools

Umami Selfhosted

On our website, the analysis tool Umami (Selfhosted) is used, an open-source software for web analysis provided by Umami (founded by Mike Chen, no separate company address), but operated entirely on our own servers and controlled by us. The service enables the collection and evaluation of anonymized key figures about website visits, session duration, traffic sources, referrers, used end devices (browser, operating system, device type), accessed pages as well as custom events defined by us (such as button clicks or form submissions), without storing personal data. Only anonymized usage data is processed; identification of visitors is excluded, as in particular no IP addresses are stored and no cookies are set. The purpose of data processing is the analysis of website usage, the optimization of our online presence, and the evaluation of marketing measures, in particular to improve the functionality, user-friendliness, and reach of the website. The legal basis for processing is Art. 6 Para. 1 lit. f GDPR, as there is an overriding legitimate interest in the anonymized reach analysis and improvement of the website. Umami Selfhosted does not use cookies. A transfer of personal data to third countries does not take place, as all data is stored and processed solely on our own servers within the EU. Data is recorded exclusively in anonymized form; deletion is not required as it cannot be assigned to a specific person and no personal data is processed. Further information can be found in the general data protection information on the software at https://umami.is/privacy.

3.5 Social Media Profiles

In addition to our website, we are also present with our company on social networks. Here we want to present our company and create the opportunity to get in touch with us.

Furthermore, we also use the opportunity to place advertisements and job postings in social media.

In the following, we inform you about which data we and the respective social network process when you visit and interact with our profile.

Facebook

We operate a Facebook fan page at https://www.facebook.com/. This social network is operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Interaction with our company profile

When visiting our Facebook profile and interacting with us through it, we process personal data. On the one hand, the data made publicly available on the profile. On the other hand, also the personal data contained in posts, comments or direct messages to us. Through interactions such as liking or sharing, we can see the user profile with the public information. The legal basis for this processing is Art. 6 Para. 1 lit. f GDPR. It is in our legitimate interest to provide relevant and interesting content and to enable the use and functionality of our Facebook profile. Insofar as a request is related to the fulfillment of a contract or is necessary to carry out pre-contractual measures, our processing is based on Art. 6 Para. 1 lit. b GDPR.

Page Insights

As explained in the Meta Privacy Policy under "How do we use your information?", Meta also collects and uses information to provide analytics services, so-called Page Insights, for page operators. This also applies to our Facebook page. Page Insights are aggregated statistics that are created based on certain interactions of visitors with pages and the content associated with them (e.g. viewing a page or video, subscribing to a page, marking a page with "Like" or "Unlike", etc.) and logged by Meta servers. Meta provides us with aggregated statistics and insights in connection with the Page Insights that give us information about how people interact with our company page. We do not get access to personal data, but only to the aggregated Page Insights. With the help of the Page Insights, we can view anonymous statistics, e.g. the reach of our account, page views, likes, etc. These also contain evaluations by age, gender and location of the users (as stated by them in their respective Facebook profiles). For the evaluation of the reach, we can make settings or set corresponding filters regarding the selection of a period, the consideration of a specific post as well as the demographic groupings. This data is anonymized. Conclusions about specific persons are not possible for us. The processing of this data serves the purpose of analyzing our reach and adapting our content and ads to user interests so that visitors can derive the greatest possible benefit from it. Based on the evaluations of this data, we can see how our content, our profile and our advertising are consumed. This allows us to create target group-oriented content and place advertising to better market our company and our services. The processing is based on our legitimate interest according to Art. 6 Para. 1 S. 1 lit. f GDPR. When processing personal data in the course of the so-called Page Insights, the processing takes place under joint controllership with Facebook according to Art. 26 Para. 1 GDPR. We have concluded a corresponding agreement with Facebook for this, which can be viewed here: https://www.facebook.com/legal/terms/page_controller_addendum. The contact details of Facebook are: Online contact: https://www.facebook.com/help/contact/1650115808681298 Postal: Meta Platforms Ireland Limited, ATTN: Privacy Operations, Merrion Road, Dublin 4, D04 X2K5, Ireland. For Facebook, you can contact the data protection officer under the following link: https://www.facebook.com/help/contact/540977946302970. Further information about the Page Insights: https://de-de.facebook.com/legal/terms/page_cntroller_addendum

Processing of personal data and cookies by Meta

When accessing a Facebook page, the IP address assigned to the end device is transmitted to Facebook. According to Facebook, this IP address is anonymized (for "German" IP addresses). Facebook also stores information about the end devices of its users (e.g. as part of the "login notification" function); if necessary, Facebook can thus assign IP addresses to individual users. Anyone currently logged into Facebook has a cookie with a Facebook identifier on their end device. This enables Facebook to understand who visited this page and how it was used. Via Facebook buttons integrated into websites, Facebook is able to record visits to these websites and assign them to the Facebook profiles. Based on this data, content or advertising can be offered personally tailored. Information on how personal data can be managed or deleted can be found in Facebook's Privacy Center: https://www.facebook.com/privacy/center/. Further information on the handling of data by Facebook can be found here: http://de-de.facebook.com/about/privacy.

Instagram

We operate an Instagram profile. This social media platform is offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Interaction with our company profile

When visiting our Instagram profile and interacting with us through it, we process personal data. On the one hand, the data made publicly available on the profile. On the other hand, also the personal data contained in posts, comments or direct messages to us. Through interactions such as liking or sharing, we can see the user profile with the public information. The legal basis for this processing is Art. 6 Para. 1 lit. f GDPR. It is in our legitimate interest to provide relevant and interesting content and to enable the use and functionality of our Instagram profile. Insofar as a request is related to the fulfillment of a contract or is necessary to carry out pre-contractual measures, our processing is based on Art. 6 Para. 1 lit. b GDPR.

Insights

As explained in the Meta Privacy Policy under "How do we use your information?" (https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect), Meta also collects and uses information to provide analytics services, so-called Insights, for page operators. This also applies to our Instagram profile. Insights are aggregated statistics that are created based on certain interactions of visitors with pages and the content associated with them and logged by Meta servers. This includes, among other things, the following information: – how many people see our products, services or content, such as posts, videos, Instagram pages, ads, shops and advertisements (if the advertising is shown on Meta products) and interact with them; – How people interact with our content, websites, apps and services; – Which group of people interacts with our content or which group of people uses our services. Meta provides us with aggregated reports and insights that give us information on how well our content, features, products and services are performing. We do not get access to personal data, but only to the aggregated reports. For the evaluation of the reach, we can make settings or set corresponding filters regarding the selection of a period, the consideration of a specific post as well as the demographic groupings. This data is anonymized. Conclusions about specific persons are not possible for us. The processing of this data serves the purpose of analyzing our reach and adapting our content and ads to user interests so that visitors can derive the greatest possible benefit from it. Based on the evaluations of this data, we can see how our content, our profile and our advertising are consumed. This allows us to create target group-oriented content and place advertising to better market our company and our services. The processing is based on our legitimate interest according to Art. 6 Para. 1 S. 1 lit. f GDPR. When processing personal data in the course of the so-called Insights, the processing takes place under joint controllership with Meta according to Art. 26 Para. 1 GDPR. We have concluded a corresponding agreement with Meta for this, which can be viewed [here](https://www.facebook.com/legal/terms/page_controller_addendum.). The contact details of Meta are: Online contact: https://www.facebook.com/help/contact/1650115808681298 Postal: Meta Platforms Ireland Limited, ATTN: Privacy Operations, Merrion Road, Dublin 4, D04 X2K5, Ireland. For Instagram, you can contact the data protection officer under the following link: https://www.facebook.com/help/contact/540977946302970. Further information about the Insights: https://de-de.facebook.com/help/pages/insights. The full Privacy Policy of Instagram: https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect

Processing of personal data and cookies by Meta

When accessing an Instagram page, the IP address assigned to the end device is transmitted to Meta. According to Meta, this IP address is anonymized (for "German" IP addresses). Meta also stores information about the end devices of its users (e.g. as part of the "login notification" function); if necessary, Meta can thus assign IP addresses to individual users. If you are currently logged into Instagram as a user, there is a cookie with the Instagram identifier on your end device. This enables Meta to understand who visited and used this page. Via Meta buttons integrated into websites, Meta is able to record your visits to these websites and assign them to your Instagram profile. Based on this data, content or advertising can be offered personally tailored. Further information: https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect

Mastodon

We use the decentralized social media service Mastodon and operate an account there.

General

Mastodon is a decentralized social network consisting of independent servers that can communicate with each other. Users can join any server and share content such as texts, images and videos. It is an open-source platform based on the ActivityPub protocol and makes it possible to interact with other platforms. You can find more information on the official Mastodon website joinmastodon.org. The independent servers are called instances. Each instance is operated by a person, a group or an organization and has its own rules, moderation guidelines and community norms. Mastodon allows users to join different instances with different thematic focuses and rules.

Interactions with our profile

People who follow our account are displayed publicly. If a message is transmitted to us, the date and time are saved along with the information as to which application was used for it. Such messages can contain media attachments such as images and videos. Direct posts ("direct messages") are not end-to-end encrypted and are therefore basically visible to the administrators of the instance used as well as the recipient instance. In this respect, no sensitive personal data should be transmitted to us via this channel. All interactions with the account (sharing, boosting or quoting posts) are also displayed publicly. This applies both to actions by third parties in relation to our posts and to those of our account in relation to posts from third parties.

Processing by administrator of the instance

The administrator of a Mastodon instance has access to different types of data and information when users interact on their server. This information is necessary to manage the operation of the instance and ensure that the community guidelines are adhered to. Here is some of the data that an administrator can typically see:

**User accounts:** The administrator has access to information about all user accounts registered on their instance. This includes usernames, profile information, profile pictures and header pictures.**Posts and activities:** The administrator can monitor posts and activities of users on their instance. This includes public posts, private messages and activities such as likes and reposts.**Moderation history:** Administrators can view the history of moderation actions, including blocked users, deleted posts and other measures to enforce the community guidelines.**Server logs:** The server logs contain information about the traffic on the instance, IP addresses of users and other technical details. This is important for security and protection against abuse. Mastodon also offers functions for encrypting private messages to ensure the security of communication between users. The exact data an administrator can access can vary depending on the individual configurations and settings of the instance. Further information can be found in the privacy notice of the instance on which we operate our account.

Processing by Mastodon

Mastodon itself, the developers and the central Mastodon platform generally do not receive any personal data or information about the interactions of the users on the various instances of the Mastodon network. This is a central aspect of Mastodon's decentralized and federated model. The data and information collected when interacting with user profiles on Mastodon instances remain mostly on the instance where the interaction takes place. This data is generally limited to usernames, profile information, public posts and activities within the instance. The decentralized nature of Mastodon ensures that data control lies largely with the instance administrators and the users themselves. The central Mastodon platform plays no role in managing or storing this user data, unless it involves system-relevant information for the maintenance and operation of the entire Mastodon network.

YouTube

The social profile and functions of YouTube are integrated on our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. YouTube enables the presentation of video content, the increase in reach and user interaction as well as the presentation of social media profiles directly on the website. As part of the integration, YouTube processes personal data such as IP addresses, unique identifiers (e.g. device or browser IDs), usage and interaction data (such as watched videos, playback times and click activities), demographic and preference information as well as information obtained via cookies and similar technologies. The purpose of data processing is the provision of video content, the presentation of the YouTube profile, the improvement of the user experience as well as the analysis of interactions to optimize the website and increase reach. As a rule, the legal basis is Art. 6 Para. 1 lit. a GDPR in conjunction with § 25 Para. 1 TDDDG, provided that consent to processing and to the setting of cookies and similar technologies has been granted. For purely technical, strictly necessary processes, Art. 6 Para. 1 lit. f GDPR can be authoritative. Through the integration, cookies of various categories are set, in particular analysis and marketing cookies. These cookies are only set after active consent; their functionality depends on the selected privacy settings of the integrated YouTube player. A transfer of personal data to third countries, in particular to the USA, cannot be ruled out. For data transfers, Google uses the EU Standard Contractual Clauses in accordance with Art. 46 Para. 2 and 3 GDPR as suitable guarantees. Personal data is deleted when the purpose ceases to exist, consent is revoked or upon request, provided there are no statutory retention periods. Further information is available at https://policies.google.com/privacy?hl=en.

TikTok

We operate a TikTok channel. TikTok is provided by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (hereinafter "TikTok Ireland"). Through our TikTok channel, we get the opportunity to present ourselves to the users of TikTok and to get in touch with them.

Interactions with our TikTok channel

Users can interact with our TikTok channel via their TikTok account, for example by liking or commenting on our posts. In doing so, we process the associated data such as the username and the profile picture. We use this data to optimize our content and its presentation and to adapt it to the respective user interests. Furthermore, it is possible to send us direct messages on our TikTok channel. Here, too, the username and profile picture are displayed to us. The legal basis of the data processing is Art. 6 Para. 1 lit. f GDPR. We have a legitimate interest in the optimization of our TikTok channel and the content published there. In addition, we have a legitimate interest in communicating with users in order to answer questions, respond to criticism, build a relationship and exchange information. In this way, we can improve our services and respond to the needs of potential customers. With communication via TikTok, we reach younger clientele in particular. Comments are stored permanently on the channel and can be viewed by other users. The same applies to the use of the like function and direct messages.

TikTok Analytics

When calling up and using our TikTok channel, data for TikTok Analytics is additionally processed. These are aggregated statistics that are created and logged by TikTok based on certain interactions of the visitors with our TikTok channel and provide information about how our channel is interacted with. This data includes, but is not limited to:

Follower growthVideo viewsProfile viewsLikes, comments and sharesAverage watch timePercentage of viewers who watch the entire videoSources of traffic (e.g. Profile, For You feed)Geographic distribution of the audienceActivity times of followers.

The data is provided to us in aggregated form as statistics. We do not get access to personal data, but only to the aggregated statistics. Further information on TikTok Analytics can be found here: https://www.tiktok.com/creators/creator-portal/en-us/tiktok-content-strategy/understanding-your-analytics/. The processing of this data serves exclusively for the analysis and improvement of the content on our TikTok channel. Based on the evaluations of this data, we can see how our content and our TikTok channel are consumed. This allows us to create target group-oriented content and, if necessary, place advertising to better market our company and our services. The processing is based on our legitimate interest according to Art. 6 Para. 1 S. 1 lit. f GDPR. When processing personal data in the course of TikTok Analytics, the processing takes place under joint controllership with TikTok according to Art. 26 Para. 1 GDPR. We have concluded a corresponding agreement with TikTok for this, which can be viewed here. The contact details of TikTok are: Online contact: https://privacytiktok.zendesk.com/hc/en-us/requests/new. Postal: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. Via this form you can contact the data protection officer of TikTok: https://www.tiktok.com/legal/report/DPO.

Processing of personal data by TikTok

When using the offers of TikTok, TikTok processes personal data of the users. This includes data such as your IP address, location data, time zone settings, advertising IDs, app and browser versions as well as data regarding the device (system, network type, device ID, screen resolution, operating system, audio settings and connected audio devices). The accessed TikTok profiles and channels, likes, messages and other usage data are also processed. If you are logged in with your own TikTok account, this data is assigned to your account. Further information on the processing of data by TikTok can be found here: https://www.tiktok.com/legal/page/eea/privacy-policy/en.

3.6 Third-party content

Stripe

We use the payment service Stripe on our website, which is used for processing online payments and managing subscriptions and invoices. Stripe is offered by Stripe Technology Europe, Ltd., The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland. Stripe enables the secure processing of payment processes, offers functions for fraud prevention as well as analyses and evaluations regarding payments. As part of the use of Stripe, various personal data is processed, including payment and financial data (e.g. card or account information, transaction data), identity and contact data (e.g. name, e-mail address, billing and shipping addresses, phone number, tax identification number, identity documents), device and location data (e.g. device ID, IP address), data for fraud prevention (e.g. risk and transaction ratings) as well as other usage and analysis data. The processing of this data takes place for payment processing, fraud prevention, for accounting and for the fulfillment of contractual obligations. The legal basis is Art. 6 Para. 1 lit. b GDPR for the fulfillment of a contract as well as Art. 6 Para. 1 lit. f GDPR due to our legitimate interest in secure and efficient payment processing; if consent is given for analysis or profiling functions, Art. 6 Para. 1 lit. a GDPR in conjunction with § 25 Para. 1 TDDDG applies. Stripe sets functional and, depending on the configuration, also analysis or marketing cookies that are technically necessary for payment processing or used for analysis and optimization purposes; these are – unless strictly necessary – only set after consent. A transfer of personal data to third countries, in particular the USA, may occur. Stripe uses the EU Standard Contractual Clauses in these cases as a suitable guarantee to ensure an adequate level of data protection. The storage duration depends on statutory retention obligations. Data is deleted as soon as it is no longer required for the purpose, but at the latest after expiry of statutory retention periods or upon revocation of consent, provided this does not conflict with any legal obligations. Further information can be viewed at https://stripe.com/privacy.

3.7 Payment services

Stripe

The payment service Stripe is integrated on the website to enable the secure and efficient processing of online payments and subscriptions. Stripe Payments Europe, Limited, 3 Dublin Landings, North Wall Quay, Dublin 1, D01 C4E0, Ireland is responsible for the service in Europe. Stripe provides various payment functions, such as payment by credit card, direct debit, Sofortüberweisung or digital wallets as well as automated invoicing and fraud prevention. In the course of use, Stripe processes personal data such as name, e-mail address, telephone number, billing and delivery address, credit card and account data, IP address, device and browser information, usage and transaction data as well as possibly documents for identity confirmation. The processing takes place for the purpose of payment processing, contract execution, fraud prevention and compliance with legal requirements. The legal basis is Art. 6 Para. 1 lit. b GDPR for contractual or pre-contractual measures, possibly Art. 6 Para. 1 lit. f GDPR due to legitimate interests in secure payment processing as well as § 25 Para. 2 No. 2 TDDDG for technically necessary cookies and technologies. Stripe uses technically necessary cookies as part of the payment process, including authentication and security cookies as well as session IDs for fraud prevention and payment processing. These cookies are strictly necessary for the operation and are processed without consent (§ 25 Para. 2 No. 2 TDDDG). Analytical or marketing cookies, however, are only used after consent according to § 25 Para. 1 TDDDG in conjunction with Art. 6 Para. 1 lit. a GDPR. A transfer of personal data to third countries (in particular the USA) may take place as part of the payment processing. Stripe uses the Standard Contractual Clauses approved by the EU Commission as suitable guarantees in accordance with Art. 46 Para. 2 lit. c GDPR. Personal data is generally deleted as soon as it is no longer required for achieving the purposes and there are no statutory retention obligations. In the event of a revocation of consent or after expiry of statutory periods, the data is deleted, provided no other statutory retention periods stand in the way. Further information on data processing by Stripe is available at: https://stripe.com/privacy

SEPA Credit Transfer (Bank transfer)

We use the SEPA Credit Transfer for payment processing on our website. The SEPA Credit Transfer is a payment service according to the standard of the European Payments Council (EPC), Rue d'Arlon 73, 1050 Brussels, Belgium, and is processed via the respectively commissioned bank or the respective Payment Service Provider (PSP). The SEPA transfer enables transfers in euros within the SEPA area to be processed in a standardized and efficient manner, e.g. in the context of online purchases, recurring billing or direct payments between accounts. Personal data such as the name and IBAN of the payer and recipient, the transfer amount, an optional purpose and possibly the BIC are typically processed. The purpose of the processing is the execution and handling of payments within the SEPA procedure, including legally prescribed obligations for fraud prevention and money laundering combat. The legal basis of the data processing is Art. 6 Para. 1 lit. b GDPR for the fulfillment of a contract as well as legal obligations according to Art. 6 Para. 1 lit. c GDPR. No cookies are used in the context of a SEPA transfer. Data transmission basically takes place within the EU and the EEA. A transfer to third countries does not take place unless the recipient bank is located abroad; in this case, the legal requirements for international data transfer according to the GDPR apply and the respective provided guarantees (e.g. EU Standard Contractual Clauses) are used. Personal data is stored for the duration of statutory retention periods (e.g. according to commercial and tax law) and subsequently deleted, provided there are no other legitimate reasons for retention. Further information on data processing in SEPA transfers can be found in the privacy policy of the respectively commissioned bank or the commissioned payment service provider.

3.8 Services for order processing

Packlink Pro

Packlink Pro is used on this website, a shipping management and order processing service of Auctane, S.L.U., Paseo Imperial, 14, 28005 Madrid, Spain. Packlink Pro enables the automated administration and optimization of shipping processes, including the integration of online shop orders, the comparison of shipping service providers, the printing of shipping labels in large quantities and the tracking of shipments. The personal data typically processed includes e-mail address, personal details, billing address, contact data, login password, language settings, web traffic and session data as well as information from analytical and functional cookies. The purpose of the data processing is the automation and optimization of shipping processing, the provision of shipping options in the ordering process, the creation and management of shipping labels and the provision of tracking information for end customers. The legal basis for the data processing is Art. 6 Para. 1 lit. b GDPR, insofar as the processing is necessary for the implementation of pre-contractual measures or for the fulfillment of a contract regarding the shipping; in addition, Art. 6 Para. 1 lit. f GDPR can be invoked to safeguard legitimate interests in the context of shipping optimization. Insofar as analytical and functional cookies are used, their storage is based on a given consent according to Art. 6 Para. 1 lit. a GDPR in conjunction with § 25 Para. 1 TDDDG. These cookies can be used, among other things, to evaluate web traffic and improve user-friendliness. A transfer of personal data to third countries does not take place according to current knowledge; the data processing takes place in Spain and thus within the EEA. The storage duration is based on the necessity for purpose fulfillment; data is deleted as soon as it is no longer required for the purposes of processing or a given consent is revoked, provided this does not conflict with statutory retention periods. Further details on data protection at Packlink Pro can be found at https://support-pro.packlink.com/hc/en-gb/articles/360010011560-Privacy-and-Cookies-policy.

3.9 Shipping service providers

For the dispatch of goods ordered via our website, we work together with various shipping service providers (e.g. DHL, DPD, UPS, Hermes). Within the scope of the necessary delivery of the goods, we pass on your data (name, delivery address and possibly further information necessary for shipping) to the respective shipping service provider.

The data transmission takes place on the basis of Art. 6 Para. 1 lit. b GDPR for the fulfillment of our contract. We only transmit your e-mail address or telephone number to the shipping service provider if you have expressly consented to this in the ordering process, for example to enable a parcel announcement. This consent can be revoked at any time for the future.

Further information on the data protection of our shipping service providers can be found in their respective privacy policies, which can be viewed on their websites.

3.10 Cancellation button

On our website/platform, we provide an electronic cancellation function via which a contract concluded with us can be revoked.

When using this function, we process the data required to handle the cancellation, in particular order/contract data (e.g. order number, date of contract conclusion), contact data (name, e-mail address) as well as the time of the declaration of revocation.

The legal basis is Art. 6 Para. 1 lit. b GDPR (reversal of the contract) as well as Art. 6 Para. 1 lit. c GDPR in conjunction with commercial and tax law retention obligations. The data is deleted after the statutory retention periods have expired.

3.11 Online marketplaces

We sell goods or services on online marketplaces. For this purpose, we use the following providers:

Amazon

We operate an Amazon shop. Amazon is offered by Amazon Europe Core S.à r.l., 38 avenue John F. Kennedy, L-1855 Luxembourg.

Data processing by Amazon

When visiting our Amazon shop, Amazon primarily processes personal data. How this data processing works in concrete terms and which data is processed by Amazon can be read in Amazon's Privacy Notice: https://www.amazon.de/gp/help/customer/display.html?nodeId=GX7NJQ4ZB8MHFRNJ.

Data processing by us

If an item or service is purchased via our Amazon shop, we receive from Amazon the user name of the purchasing person and the billing and delivery address. Insofar as the "Fulfillment by Amazon" takes place, Amazon manages the delivery, is responsible for customer service and takes care of all problems in connection with the order. Further information on this can be found here: https://www.amazon.de/gp/help/customer/display.html?nodeId=G239KSGYPUFUY8TQ. If the items are not marked with "Fulfillment by Amazon", we manage the delivery of the order ourselves. Further information on this can be found here: https://www.amazon.de/gp/help/customer/display.html?nodeId=GEF528GN65XSJ7V8 In this case, we also process all inquiries to customer service, unless we indicate that customer service is provided by Amazon or the order is marked with the Amazon Prime sign.

Payment processing

Amazon handles the payment processing. We do not receive any payment information. Amazon only forwards the executed payment to us.

Etsy

We operate an Etsy shop. Etsy is offered by Etsy Ireland UC, 66/67 Great Strand Street, Dublin 1, Ireland.

Data processing by Etsy

When visiting our Etsy shop, Etsy primarily processes your personal data. How this data processing works in concrete terms and which data is processed by Etsy can be read in Etsy's Privacy Policy: www.etsy.com/de/legal/privacy. Etsy also uses various cookies. We have no access to the cookies and neither to the associated data. More details on this can be found here: www.etsy.com/de/legal/cookies-and-tracking-technologies.

Data processing by us

a) Conclusion of contract via the Etsy shop When concluding a contract with us via Etsy, we receive from Etsy the Etsy username (unless the purchase is made as a "guest"), the name and the billing address as stored in the Etsy user account or provided in the course of the contract conclusion. If further data is provided as part of the order (e.g. a different delivery address or a telephone number), this will also be transmitted to us by Etsy. We process this data for the proper fulfillment of the contract, in particular for delivery, invoicing, recording of payments and processing of returns and complaints. If we have committed to providing updates for a digital product or for goods with digital elements, we also process the contact data for this purpose. The legal basis of the data processing is Article 6 Para. 1 lit. b GDPR. We store this data until all mutual claims from the respective contractual relationship are completely settled and statutory retention periods have expired. b) Passing on data for transport Insofar as we send physical goods based on the purchase contract, we transmit the name and address of the recipient and, if we have consent in this regard, the e-mail address, for the purpose of delivering the shipment. The legal bases for this are Art. 6 Para. 1 lit. a and b GDPR. c) Contacting If a message is sent to us via Etsy, Etsy transmits to us the Etsy username, or if this is not available, another sender identification along with the message. The legal basis for this data processing is Art. 6 Para. 1 lit. a GDPR. If a message is sent to us by e-mail, we save the message with the sender data (name, e-mail address) in order to answer it and also be able to react to possible later follow-up questions. The legal basis for this data processing is Art. 6 Para. 1 lit. f GDPR. If a legally relevant declaration regarding the contractual relationship is transmitted to us (such as a cancellation or a complaint), the legal basis for our processing of the data is Art. 6 Para. 1 lit. b GDPR. In such a case, we delete the data related to the declaration as soon as all mutual claims from the contractual relationship have finally been settled and the commercial and tax law retention periods have expired.

Payment processing

For the payment of a purchase, the chosen payment service provider collects and processes the name, the card or account number and/or other data required for the respective payment method. The privacy policies of the chosen payment service provider apply in this respect, and, if the recipient of the payment is Etsy, the Privacy Policy of Etsy.

Social media buttons

Social media buttons may be displayed on the pages of Etsy, which can be recognized by the logos of the social media platforms. These are pure links to the respective platforms. A click on such a link calls up the website of the respective platform. In doing so, the IP address of the calling end device and the address of the corresponding Etsy page from which the link is made ("referrer") are transmitted to the called-up platform. However, we ourselves do not process any data in this process.

eBay

We operate an eBay Shop. eBay is offered by eBay GmbH, Albert-Einstein-Ring 2-6, 14532 Kleinmachnow, Germany.

Data processing by eBay

We expressly refer to the privacy notice of eBay, in which eBay provides comprehensive information about its data processing: https://www.ebay.de/help/policies/member-behaviour-policies/user-privacy-notice-privacy-policy?id=4260. Upon registration, eBay has obtained a corresponding consent both regarding the scope of data collection and the purpose and type of processing and storage of personal data.

Data processing by us

We do not collect any further personal data beyond that collected by eBay. We store the data transmitted to us by eBay and use it for the following purposes:

for customer identification;to be able to process, fulfill and handle orders;for correspondence;for invoicing;for the processing of any existing liability claims, as well as the assertion of any claims.

Consent to the passing on of data for these purposes was given upon registration. The legal basis of the data processing is Art. 6 Para. 1 S. 1 lit. b GDPR, in order to appropriately process the order and to mutually fulfill the obligations arising from the purchase contract. The personal data collected by eBay for the processing of the order and transmitted to us will be stored by us until the expiry of the statutory retention obligation and then deleted, unless we are obligated to longer storage according to Article 6 Para. 1 S. 1 lit. c GDPR due to tax and commercial law retention and documentation obligations (from HGB, StGB or AO) or you have consented to storage going beyond this according to Art. 6 Para. 1 S. 1 lit. a GDPR.

Payment processing

Various payment service providers can be selected in our eBay Shop for processing the ordering process. By way of "Payment processing by eBay", eBay S.à.r.l., 22-24 Boulevard Royal, L2449 Luxembourg ("eBay") initially collects the required payment data. If paying by direct debit or credit card, eBay processes the payment itself. For all other payment methods, eBay transmits the required payment data for executing the payment to the selected payment service provider:

Paypal

PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full.

Apple Pay

Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland.

Google Pay

Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

Klarna

Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden, https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf, https://www.klarna.com/de/datenschutz/.

Giropay

Paydirekt GmbH, Hamburger Allee 26-28, 60486 Frankfurt am Main, Germany, https://www.paydirekt.de/agb/index.html.

Sofortüberweisung

Sofort GmbH, Theresienhöhe 12, 80339 Munich, Germany, https://www.sofort.de/datenschutz.html, https://www.klarna.com/sofort/.

VISA

of Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, Great Britain, https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html. The legal basis for processing is Art. 6 Para. 1 lit. b GDPR. Further information can be found here: https://pages.ebay.de/payment/2.0/terms.html.

4. What else is important

Finally, we would like to inform you in detail and comprehensively about your rights and tell you how you will be informed about changes in the data protection requirements.

4.1 Your rights in detail

4.1.1 Right of access under Art. 15 GDPR

You can request information as to whether personal data concerning you is processed. If this is the case, you can request further information on the nature and manner of the processing. A detailed list can be found in Art. 15 Para. 1 lit. a to h GDPR.

4.1.2 Right to rectification under Art. 16 GDPR

This right includes the rectification of inaccurate data and the completion of incomplete personal data.

4.1.3 Right to erasure under Art. 17 GDPR

This so-called 'right to be forgotten' gives you the right, under certain conditions, to request the controller to erase your personal data. This is basically the case when the purpose of the data processing has ceased to exist, if consent has been revoked or the initial processing took place without a legal basis. A detailed list of reasons can be found in Art. 17 Para. 1 lit. a to f GDPR. This "right to be forgotten" also corresponds to the obligation of the controller under Art. 17 Para. 2 GDPR to take reasonable steps to bring about a general erasure of the data.

4.1.4 Right to restriction of processing under Art. 18 GDPR

This right is linked to the conditions according to Art. 18 Para. 1 lit. a to d.

4.1.5 Right to data portability under Art. 20 GDPR

This regulates the fundamental right to receive one's own data in a common format and to transmit it to another controller. However, this only applies to data from processing based on consent or a contract under Art. 20 Para. 1 lit. a and b and insofar as this is technically feasible.

4.1.6 Right to object under Art. 21 GDPR

You can generally object to the processing of your personal data. This applies in particular if your interest in objecting outweighs the legitimate interest of the controller in processing and if the processing relates to direct marketing and or profiling.

4.1.7 Right to "decision in individual cases" under Art. 22 GDPR

You basically have the right not to be subject to a decision based solely on automated processing (including profiling), which produces legal effects concerning you or similarly significantly affects you. However, this right also finds restrictions and additions in Art. 22 Para. 2 and 4 GDPR.

4.1.8 Other rights

The GDPR includes comprehensive rights to inform third parties as to whether or how you have asserted rights under Art. 16, 17, 18 GDPR. However, this only to the extent that this is also possible or feasible with reasonable effort.

At this point, we would like to draw your attention again to your right to revoke given consent according to Art. 7 Para. 3 GDPR. The lawfulness of the processing carried out up to that point is not affected by this, however.

In addition, we would also like to point out your rights under §§ 32 et seq. BDSG, which, however, are largely identical in content to the rights just described.

4.1.9 Right to lodge a complaint under Art. 77 GDPR

You also have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data relating to you infringes this Regulation.

5. What happens if the GDPR is abolished tomorrow or other changes take place?

From time to time, it is necessary to adapt the content of the privacy policy in order to react to factual and legal changes. We therefore reserve the right to change this privacy policy at any time. We will publish the amended version in the same place and recommend that you read the privacy policy regularly. The current status of this privacy policy is noted below this paragraph. 

Last update