Privacy Policy
Hosting
2. Data processing for the fulfilment of contracts and for establishing contact
2.1 Data processing for the fulfilment of contracts
2.2 Customer account
2.3 Microsoft 365, including Outlook and Microsoft 365 Copilot
2.4 Contacting us
3. Data processing for the purpose of order fulfilment
Disclosure of data to delivery service providers for the purpose of dispatch notifications
4. Data processing for payment processing
4.1 Data processing for transaction processing
4.2 Data processing for the purposes of fraud prevention and optimising our payment processes
4.3 Identity and credit checks when selecting Klarna payment services
5. Advertising by email
5.1 EmailNewsletter with login details, Newsletter tracking with separate consent
5.2 Newsletter distribution
5.3 Sending review requests by email
6. Cookies and other technologies
6.1 General information
6.2 Consent Manager Platform (CMP)
6.3 Information on transfers to third countries (data transfers to third countries)
7. Use of cookies and other technologies
7.1 Use of Google services
7.2 Use of Facebook services
7.3 Other providers of web analytics and online marketing services
8. Integration of the Trusted Shops Trustbadge/ other widgets
8.1 Data processing when the Trustbadge/ other widgets are integrated
8.2 Data processing after completion of an order
9. Social media
9.1 Social media buttons from Facebook (by Meta) and Instagram (by Meta)
9.2 Our online presence on Facebook (by Meta), Instagram (by Meta), YouTube, Pinterest, LinkedIn and Xing
10. Contact details and your rights
10.1 Your rights
10.2 Contact details
The data controller is:
travelite GmbH + Co. KG
Merkurring 70-72
22143 Hamburg
Email: info@travelite.de
We appreciate your interest in our online shop. Protecting your privacy is very important to us. Below, we provide detailed information on how we handle your data.
1. Access data and hosting
You may visit our web pages without providing any personal information. Each time a web page is accessed, the web server automatically stores a so-called server log file, which contains, for example, the name of the file requested, your IP address, the date and time of the request, the volume of data transferred and the requesting provider (access data), and documents the request. This access data is analysed solely for the purpose of ensuring the smooth operation of the site and improving our service. This serves to safeguard our legitimate interests, which prevail following a balancing of interests, in the correct presentation of our services in accordance with Article 6(1)(f) of the GDPR. All access data is deleted no later than seven days after the end of your visit to the site.
Hosting
The services relating to the hosting and display of the website are partly provided by our service providers as part of data processing on our behalf. Unless otherwise stated in this privacy policy, all access data and all data collected via the forms provided for this purpose on this website are processed on their servers. If you have any questions regarding our service providers and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has determined, by means of a decision, that an adequate level of data protection exists: the United Kingdom, Canada and the USA.
There is a decision by the European Commission on an adequate level of data protection for the USA as the basis for a transfer to a third country, provided that the relevant service provider is certified. Pending certification by our service providers, data transfers will continue to be based on the following: the European Commission’s Standard Data Protection Clauses
Our service providers are based in and/or use servers in the following countries: Australia.
There is no adequacy decision by the European Commission for these countries. Our cooperation with you is based on these safeguards: the European Commission’s Standard Data Protection Clauses.
2. Data processing for contract fulfilment and for establishing contact
2.1 Data processing for the performance of a contract
For the purpose of contract fulfilment (including enquiries regarding and the handling of any existing warranty claims and claims for breach of contract, as well as any statutory obligations to provide updates) in accordance with Article 6(1)(b) of the GDPR, we collect personal data if you voluntarily provide it to us as part of your order. Mandatory fields are marked as such, as in these cases we absolutely require the data for the performance of the contract and cannot dispatch the order without it. The data collected is specified in the relevant input forms.
Further information on the processing of your data, in particular regarding its disclosure to our service providers for the purposes of order processing, payment processing and dispatch, can be found in the following sections of this privacy policy. Once the contract has been fully fulfilled, your data will be restricted for further processing and deleted upon expiry of the retention periods under tax and commercial law in accordance with Article 6(1), first sentence, point (c) of the GDPR, unless you have expressly consented to the further use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy.
Merchandise management system
We use external service providers’ merchandise management systems for order and contract processing. Our service providers act on our behalf within the framework of data processing on our behalf. If you have any questions regarding our service providers or the basis of our cooperation with them, please use the contact details provided in this privacy policy.
2.2 Customer account
Insofar as you have given your consent to this in accordance with Article 6(1)(a) of the GDPR by choosing to open a customer account, we will use your data for the purpose of opening the customer account and for storing your data for future orders on our website. You may delete your customer account at any time, either by contacting us via the contact details provided in this privacy policy or by using the function provided for this purpose within your customer account. Once your customer account has been deleted, your data will be deleted, unless you have expressly consented to the continued use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy.
2.3 Microsoft 365, including Outlook and Microsoft 365 Copilot
We use ‘Microsoft 365’, including Outlook and Microsoft 365 Copilot. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (hereinafter referred to as ‘Microsoft’).
Microsoft 365 is a platform for communication, collaboration, appointment management, file storage, document editing and the organisation of business processes. When using Microsoft 365, the following data in particular may be processed: master data, contact details, communication data, content data, email data, file and document content, appointment and calendar data, contract data, usage data, technical data and metadata. When using Outlook, the following data in particular may be processed: names, email addresses, email content, email attachments, subject lines, send and receive times, and other communication metadata.
We also use Microsoft 365 Copilot to support our work with Microsoft 365. Depending on usage, configuration and the authorisation scheme, Microsoft 365 Copilot may process content from Microsoft 365. This may include, in particular, emails, calendar information, contacts, files, document content, meeting content, chat and communication data, as well as other information from Microsoft 365. This processing is carried out, in particular, for the purposes of searching for information, summarising content, creating and revising texts, preparing work processes and supporting internal organisation. Microsoft 365 Copilot processes content within the scope of the authorised access policy that has been set up and, in principle, can only take into account content to which the respective user is authorised to access.
The processing of personal data may also take place in third countries, in particular in the USA. This may be the case, in particular, for support services, security and error analyses, telemetry, the use of sub-processors or, depending on the configuration of individual Microsoft services. In the case of Microsoft 365 Copilot, depending on settings and the availability of features, individual processing operations – in particular processing by large language models – may also take place outside the EU Data Boundary. In this regard, Microsoft describes the option of so-called ‘Flex Routing’ for EU and EFTA customers, whereby LLM inference may take place outside the EU Data Boundary under certain conditions.
Where personal data is transferred to Microsoft in the USA or processed there, Microsoft bases the data transfer to the USA on the European Commission’s EU-US Data Privacy Framework. Where Microsoft transfers personal data to other third countries or has it processed by sub-processors in other third countries, Microsoft states that it additionally bases these transfers on appropriate safeguards, in particular standard contractual clauses within the meaning of Article 46 of the GDPR.
Where processing is necessary for the implementation of pre-contractual measures or a contract with you, it is carried out on the basis of Article 6(1)(b) of the GDPR. Where processing is carried out to safeguard our legitimate interests, it is carried out on the basis of Article 6(1)(f) of the GDPR. Our legitimate interests lie in efficient communication, the secure organisation of our business processes, structured collaboration, the documentation of business transactions, the handling of enquiries, and supporting our employees in carrying out their business tasks. Where we are legally obliged to retain certain communications, documents or business transactions, the processing is carried out on the basis of Article 6(1)(c) of the GDPR. Where special categories of personal data are processed in individual cases, this will only take place if there is a legal basis for doing so in accordance with Article 9 of the GDPR.
Microsoft processes personal data, insofar as this processing is carried out on our behalf for the provision and operation of Microsoft 365, including Outlook and Microsoft 365 Copilot, as a data processor within the meaning of Article 4(8) of the GDPR. We have entered into a data processing agreement with Microsoft within the meaning of Article 28(3) of the GDPR. In this agreement, Microsoft undertakes, in particular, to process personal data only in accordance with our instructions and for the purpose of providing the agreed services, to implement appropriate technical and organisational safeguards, and to engage sub-processors only in accordance with the contractual provisions.
Further information on data processing by Microsoft can be found at https://www.microsoft.com/de-de/privacy/privacystatement . Further information on the Microsoft Products and Services Data Protection Addendum can be found at https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA
2.4 Contacting us
As part of our customer communications, we collect personal data to process your enquiries in accordance with Article 6(1)(b) of the GDPR if you voluntarily provide this to us when contacting us (e.g. via the contact form, live chat tool or email). Mandatory fields are marked as such, as we require this data in these cases to process your enquiry. The data collected is specified in the relevant input forms. Once your enquiry has been fully processed, your data will be deleted, unless you have expressly consented to the further processing of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy.
3. Data processing for the purpose of order fulfilment
To fulfil the contract in accordance with Article 6(1)(b) of the GDPR, we pass on your data to the delivery service provider commissioned to carry out the delivery, insofar as this is necessary for the delivery of the goods ordered. If you have any questions regarding our service providers and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
Disclosure of data to delivery service providers for the purpose of dispatch notifications
Provided you have given us your explicit consent to this during or after placing your order, we will, on this basis and in accordance with Article 6(1)(a) of the GDPR, pass on your email address to the selected delivery service provider, so that they can contact you prior to delivery to notify you of the delivery or to arrange a suitable time.
Consent may be withdrawn at any time by sending a message via the contact details provided in this privacy policy or directly to the delivery service provider at the contact address listed below. Following revocation, we will delete the data you have provided for this purpose, unless you have expressly consented to the continued use of your data or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy. If you have any questions regarding our service providers and the basis of our cooperation with them, please contact us using the contact details provided in this privacy policy.
DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Germany
DPD Deutschland GmbH
Wailandtstraße 1
63741 Aschaffenburg
Germany
4. Data processing for payment processing
We work with the following partners to process payments in our online shop: technical service providers, banks and payment service providers.
4.1 Data processing for transaction processing
Depending on the selected payment method, we pass on the data necessary for processing the payment transaction to our technical service providers, who act on our behalf as data processors, or to the designated credit institutions or the selected payment service provider, insofar as this is necessary to process the payment. This serves to fulfil the contract in accordance with Article 6(1), first sentence, point (b) of the GDPR. In some cases, the payment service providers collect the data required to process the payment themselves, e.g. on their own website or via a technical integration into the ordering process. In this respect, the privacy policy of the respective payment service provider applies.
If you have any questions regarding our payment processing partners and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
4.2 Data processing for the purposes of fraud prevention and optimising our payment processes
Where necessary, we may provide our service providers with further data, which they use together with the data required to process payments as our data processors for the purposes of fraud prevention and optimising our payment processes (e.g. invoicing, handling disputed payments, supporting our accounts department). In accordance with Article 6(1), first sentence, point (f) of the GDPR, this serves to safeguard our legitimate interests – which, following a balancing of interests, are deemed to prevail – in protecting ourselves against fraud and in ensuring efficient payment management.
4.3 Identity and credit checks when selecting Klarna payment services
Purchase on account via Klarna
If you opt for the payment services provided by Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter ‘Klarna’), we ask for your consent pursuant to Article 6(1)(a) of the GDPR to allow us to transfer to Klarna the data necessary for processing the payment and for carrying out an identity and creditworthiness check. In Germany, the credit reference agencies listed in Klarna’s privacy policy may be used for identity and credit checks. Klarna uses the information received regarding the statistical probability of payment default to make a balanced decision on whether to establish, fulfil or terminate the contractual relationship. You may withdraw your consent at any time by sending a message via the contact details provided in this privacy policy. This may mean that we are no longer able to offer you certain payment options. You may also withdraw your consent to this use of personal data at any time by contacting Klarna directly.
5. Advertising by email
5.1 EmailNewsletter with registration, Newsletter tracking with separate consent
If you subscribe to our ‘ Newsletter ’, we use the data required for this purpose or provided separately by you to send you our regular ‘E-Mail-Newsletter ’ on the basis of your consent in accordance with Article 6(1), first sentence, point (a) of the GDPR. You can unsubscribe from Newsletter at any time, either by contacting us via the method described below or by using the link provided for this purpose at Newsletter. Once you have unsubscribed, we will remove your email address from the mailing list, unless you have expressly consented to the further processing of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to process your data for other purposes that are permitted by law and about which we inform you in this notice.
If you have also given us your consent in accordance with Article 6(1)(a) of the GDPR to analyse our Newsletter, we will also analyse your interaction with our Newsletter by measuring, storing and evaluating open rates and click-through rates for the purpose of designing future newsletter campaigns (“Newsletter tracking”).
For the purposes of this analysis, the emails sent contain single-pixel technologies (e.g. so-called web beacons, tracking pixels) which are stored on our website. For the purposes of analysis, we link the following ‘newsletter data’
- the page from which the page was requested (known as the referrer URL),
- the date and time of the visit,
- a description of the type of web browser used,
- the IP address of the requesting computer,
- the email address,
- the date and time of registration and confirmation
and the one-pixel technologies with your email address or your IP address and, where applicable, an individual ID. Links contained within the Newsletter may also contain this ID.
You can opt out of Newsletter tracking at any time, either by sending a message via the contact details provided or by using the link provided for this purpose on Newsletter.
The information will be stored for as long as you remain a subscriber to the Newsletter.
5.1.1 Email marketing without registration via Newsletter and your right to object
If we receive your email address in connection with the sale of a product or service and you have not objected to this, we reserve the right to send you regular offers from our range. You may object to this use of your email address at any time by sending a message via the contact details provided below or via a link provided for this purpose in the promotional email, without incurring any costs other than the transmission costs in accordance with standard rates.
5.2 Newsletter distribution
Newsletter and the Newsletter tracking shown above may also be sent by our service providers as part of processing carried out on our behalf. If you have any questions regarding our service providers and the basis of our cooperation with them, please contact us using the contact details provided in this privacy policy.
5.3 Sending requests for reviews by email
Provided that you have given us your explicit consent in accordance with Article 6(1)(a) of the GDPR during or after placing your order, we will use your email address to request that you submit a review of your order via the review system we use. This consent may be withdrawn at any time by sending a message via the contact details provided in this privacy policy or via a link provided for this purpose in the review request. Once you have withdrawn your consent, we will delete your email address from the recipient list, provided that you have not expressly consented to the further processing of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to process your data for other purposes that are permitted by law and about which we inform you in this policy.
Review requests may also be sent by our service provider, Trusted Shops SE, Subbelrather Str. 15C, 50823 Cologne ("Trusted Shops").
In the course of sending review requests, we receive information from Trusted Shops regarding the respective status (e.g. whether the review request has been sent and whether it has been received). This is carried out in accordance with Article 6(1)(f) of the GDPR to fulfil our legitimate interest in receiving information about the review invitations, so that we may, where necessary, as well as to fulfil Trusted Shops’ legitimate interest in being able to offer this service.
We are jointly responsible with Trusted Shops for sending requests for reviews and for collecting and displaying review and status information.
In the context of the joint controllership arrangement between us and Trusted Shops, please contact Trusted Shops in the first instance regarding data protection queries and to exercise your rights; you can find their contact details here. Further information on data protection can be found via the following link here. Irrespective of this, you are also always welcome to contact us using the contact details provided in this privacy policy. Your enquiry will then, if necessary, be forwarded to the other data controller for a response.
6. Cookies and other technologies
6.1 General information
To make your visit to our website more engaging and to enable the use of certain functions, we use various technologies on different pages, including so-called cookies. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted at the end of the browser session, i.e. when you close your browser (so-called session cookies). Other cookies remain on your device and enable us to recognise your browser the next time you visit (persistent cookies). You can find the storage duration in the overview within your web browser’s cookie settings.
Privacy protection on end devices
When you use our online services, we employ technologies that are strictly necessary to provide the explicitly requested telemedia service. The storage of information on your device or access to information already stored on your device does not require your consent in this respect.
For functions that are not strictly necessary, the storage of information on your device or access to information already stored on your device requires your consent. Please note that if you do not give your consent, parts of the website may not be fully accessible. Any consent you have given will remain valid until you adjust or reset the relevant settings on your device.
Any subsequent data processing carried out by cookies and other technologies
We use technologies that are strictly necessary for the use of certain functions on our website (e.g. the shopping basket function). These technologies collect and process your IP address, the time of your visit, device and browser information, and details of your use of our website (e.g. information regarding the contents of your shopping basket). This is based on a balancing of interests, where our overriding legitimate interests in optimising the presentation of our services prevail, in accordance with Article 6(1), first sentence, point (f) of the GDPR.
We also use technologies to fulfil the legal obligations to which we are subject (e.g. to be able to demonstrate consent to the processing of your personal data) as well as for web analytics and online marketing. Further information on this, including the respective legal basis for data processing, can be found in the following sections of this privacy policy.
Cookie settings
You can find the cookie settings for your browser via the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™
Where you have consented to the use of these technologies in accordance with Article 6(1), first sentence, point (a) of the GDPR, you may withdraw your consent at any time by sending a message via the contact details provided in this privacy policy. Alternatively, you can also visit the following link: https://www.travelite.com/de. If you do not accept cookies, the functionality of our website may be restricted.
6.2 Consent Manager Platform (CMP)
On our website, we use a consent management service (“Consent Manager Platform (CMP)”) to inform you about the cookies and other technologies we use on our website, and to obtain, manage and document your consent – where required – to the processing of your personal data by these technologies. This is necessary in accordance with Article 6(1), first sentence, point (c) of the GDPR to fulfil our legal obligation under Article 7(1) of the GDPR to be able to demonstrate your consent to the processing of your personal data, to which we are subject. The Consent Manager Platform (CMP) used is a service provided by ACRIS E-Commerce GmbH, Am Pfenningberg 60, 4040 Linz, Austria, which processes your data on our behalf.
Once you have submitted your cookie consent on our website, the web server stores the following data: IP address, device information, browser information, language setting, the webpage accessed or its URL, the date and time of your declaration of consent, and information regarding your consent behaviour.
In addition, the following technologies are used, which contain information regarding your consent behaviour: Cookies
The data is stored exclusively on your device; no personal data is transferred to the provider of the Consent Manager Platform (CMP). Your data will be deleted after 30 days, unless you have expressly consented to the further use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data beyond this, provided such use is permitted by law and we inform you of this in this policy.
6.3 Information on transfers to third countries (data transfers to third countries)
We use technologies from service providers on our website whose registered offices and/or server locations may be situated in third countries, outside the EU or the EEA. If there is no adequacy decision by the European Commission for that country, an adequate level of data protection must be ensured by means of other suitable safeguards.
Appropriate safeguards in the form of contractually agreed standard contractual clauses issued by the European Commission or binding corporate rules (BCRs) are, in principle, possible; however, they require prior review by the contracting parties to determine whether an adequate level of protection can be guaranteed. According to the case law of the European Court of Justice, it may be necessary to implement additional safeguards for this purpose.
We have, as a matter of principle, agreed to the Standard Data Protection Clauses issued by the European Commission with the technology providers we use who process personal data in a third country. Where possible, we also agree on additional safeguards designed to ensure that an adequate level of data protection is guaranteed in third countries without an adequacy decision.
Notwithstanding this, it may be the case that, despite all contractual and technical measures, the level of data protection in the third country does not correspond to that of the EU. In such cases, we ask you, where necessary, as part of the cookie consent process, to give your consent in accordance with Article 49(1)(a) of the GDPR to the transfer of your personal data to a third country.
In particular, there is a risk that local authorities in the third country may, from a European data protection perspective, be granted access rights to your personal data that are not sufficiently restricted, that we, as the data exporter, or you, as the data subject, may not be aware of this, and/or that you may not have sufficient legal remedies available to prevent this and/or to take action against such access.
In particular, the following countries are currently classified as third countries without an adequacy decision by the European Commission (exemplary list):
- China
- Russia
- Taiwan
You can find out to which third countries we transfer data in the privacy notices for the respective tool and/or the consent management service we use (Consent Manager Platform, CMP).
7. Use of cookies and other technologies
We use the following cookies and other third-party technologies on our website. Unless otherwise stated for the individual technologies, this is done on the basis of your consent in accordance with Article 6(1)(a) of the GDPR. Once the purpose has ceased to apply and we have stopped using the relevant technology, the data collected in this context will be deleted. You may withdraw your consent at any time with effect for the future. Further information on how to withdraw your consent can be found in the section "Cookies and other technologies". Further information, including the legal basis for our cooperation with the individual providers, can be found in the sections on the individual technologies. If you have any questions regarding the providers and the legal basis for our cooperation with them, please use the contact details provided in this privacy policy.
7.1 Use of Google services
We use the technologies described below provided by Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by Google’s technologies regarding your use of our website is generally transmitted to and stored on a server belonging to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Unless otherwise specified for the individual technologies, data processing is carried out on the basis of an agreement concluded between joint controllers for the respective technology in accordance with Article 26 of the GDPR. Further information on data processing by Google can be found in Google’s privacy policy.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
Google Analytics
For the purpose of website analysis, data (IP address, time of visit, device and browser information, and information regarding your use of our website) is automatically collected and stored using Google Analytics; this data is used to create usage profiles using pseudonyms. Cookies may be used for this purpose. If you visit our website from within the EU, your IP address is stored on a server located in the EU for the purpose of deriving location data and is then immediately deleted before the traffic is forwarded to other Google servers for processing. Data processing is carried out on the basis of a data processing agreement with Google.
If you do not give in accordance with Article 6(1)(a) of the GDPR for the use of Google Analytics, no cookies will be stored on or read from your device. The data processing described in the preceding paragraphs will not take place. To fill gaps in web analytics through behavioural and conversion modelling, pings containing data (user agent, information on your consent behaviour, screen resolution, IP address) are sent to Google.
Google Ads
For advertising purposes in Google search results and on third-party websites, the so-called Google remarketing cookie is set; this automatically enables interest-based advertising through the collection and processing of data (IP address, time of visit, device and browser information, and information about your use of our website), using a pseudonymous cookie ID and based on the pages you have visited. Any further data processing only takes place if you have enabled the ‘personalised advertising’ setting in your Google account. In this case, if you are logged into Google whilst visiting our website, Google will use your data in conjunction with Google Analytics data to create and define audience lists for cross-device remarketing.
For website analysis and event tracking, we use Google Ads Conversion Tracking to track your subsequent usage behaviour if you have arrived at our website via a Google Ads advert. To this end, cookies may be used and data (IP address, time of visit, device and browser information, as well as information about your use of our website based on events specified by us, such as visiting a web page or subscribing to a newsletter) may be collected, from which usage profiles are created using pseudonyms.
If you do not do not give us in accordance with Article 6(1)(a) of the GDPR for the use of Google Ads, no cookies will be stored on or read from your device. The data processing described in the preceding paragraphs will not take place. To fill gaps in web analytics through behavioural and conversion modelling, pings containing data (user agent, information on your consent behaviour, screen resolution, IP address, page URL, information on ad clicks in URL parameters) are sent to Google. Your IP address is used to determine the country of origin.
Google Maps
For the visual display of geographical information, Google Maps collects data relating to your use of the Maps functions – in particular your IP address and location data – which is transmitted to Google and subsequently processed by Google. We have no influence over this subsequent data processing.
Google reCAPTCHA
To protect against misuse of our web forms and spam generated by automated software (so-called Bots), Google reCAPTCHA collects data (IP address, time of visit, browser information and details of your use of our website) and analyses your use of our website using JavaScript and cookies. In addition, other cookies stored in your browser by Google services are analysed. No personal data is read or stored from the input fields of the respective form.
Google Fonts
To ensure consistent presentation of content on our website, the “Google Fonts” script code collects data (IP address, time of visit, device and browser information), which is transmitted to Google and subsequently processed by Google. We have no influence over this subsequent data processing.
Google Tag Manager
Google Tag Manager enables us to manage various codes and services on our website. When implementing individual tags, Google may also process personal data (e.g. IP address, online identifiers (including cookies)). Data processing is carried out on the basis of a data processing agreement with Google.
The use of Google Tag Manager enables the integration of various services and technologies.
If you do not wish to use certain tracking services and have therefore disabled them, this deactivation will apply to all relevant tracking tags integrated via Google Tag Manager.
YouTube Video Plugin
When embedding third-party content via the YouTube video plugin in the enhanced data protection mode we use, data (IP address, time of visit, device and browser information) is collected, transmitted to Google and subsequently processed by Google, only if you play a video.
7.2 Use of Facebook services
Use of Facebook Pixel
We use the Facebook Pixel as part of the technologies described below provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Facebook (by Meta)” or “Meta Platforms Ireland”). The Facebook Pixel automatically collects and stores data (IP address, time of visit, device and browser information, as well as information on your use of our website based on events specified by us, such as visiting a webpage or subscribing to a newsletter), from which usage profiles are created using pseudonyms.
As part of what is known as ‘extended data matching’, information that can be used to identify individuals (e.g. names, email addresses and telephone numbers) is also collected and stored in hashed form for matching purposes.
To this end, when you visit our website, the Facebook Pixel automatically sets a cookie which, by means of a pseudonymous cookie ID, enables your browser to be recognised automatically when you visit other websites. Facebook (by Meta) will combine this information with other data from your Facebook account and use it to compile reports on website activity and to provide further services related to website usage, in particular personalised and group-based advertising.
The information automatically collected by Facebook (by Meta) technologies regarding your use of our website is generally transferred to and stored on a server belonging to Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Further information on data processing by Facebook can be found in Facebook’s (by Meta) privacy policy.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined an adequate level of data protection: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.
The adequacy decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been obtained.
Our service providers are based in and/or use servers in the following countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil and Mexico. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the following safeguards: the European Commission’s Standard Data Protection Clauses.
Facebook Analytics
As part of the Facebook Business tools, statistics on visitor activity on our website are compiled from the data collected via the Facebook Pixel regarding your use of our website. Data processing is carried out on the basis of a data processing agreement with Facebook (by Meta). The analysis is used to optimise the presentation and marketing of our website.
Facebook Ads (Ads Manager)
We use Facebook Ads to advertise this website on Facebook (by Meta) and on other platforms. We determine the parameters of the respective advertising campaign. Facebook (by Meta) is responsible for the precise implementation, in particular the decision on the placement of adverts for individual users. Unless otherwise specified for the individual technologies, data processing takes place on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Joint controllership is limited to the collection of data and its transfer to Meta Platforms Ireland. Subsequent data processing by Meta Platforms Ireland is not covered by this.
Based on the statistics generated via Facebook Pixel regarding visitor activity on our website, we operate a Custom Audience to run group-based advertising on Facebook (by Meta), by defining the characteristics of the respective target audience. As part of the extended data matching process carried out to determine the respective target audience (see above), Facebook (by Meta) acts as our data processor.
Based on the pseudonymous cookie ID set by the Facebook Pixel and the data collected about your usage behaviour on our website, we use the Facebook Pixel to carry out remarketing personalised advertising.
About Facebook Pixel Conversions we use to analyse your subsequent usage behaviour for web analytics and event tracking when you have arrived at our website via a Facebook Ads advertisement. Data processing is carried out on the basis of a data processing agreement with Facebook (by Meta).
7.3 Other providers of web analytics and online marketing services
use of AdCell retargeting for online marketing
use of AdCell retargeting for online marketing Through our advertising partner Firstlead GmbH, Rosenfelder Str. 15–16, 10315 Berlin (“adcell”), we advertise this website in search results and on third-party websites. When you visit our website, a retargeting cookie is automatically set by adcell or its partners; this enables interest-based advertising using a pseudonymous cookie ID and based on the pages you have visited. Data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. We determine the parameters of the respective advertising campaign. adcell is responsible for the precise implementation (e.g. deciding on the placement of individual adverts). The data automatically collected by adcell (IP address, time of visit, device and browser information, and information about your use of our website) may be combined by adcell with information from other sources and transmitted to adcell’s advertising partners.
Customa
On this website, data is collected and stored using technologies from customa for marketing and optimisation purposes. The provider of this technology is trust in dialog Services GmbH, Merkurring 33-35, 22143 Hamburg, https://www.customa.de. Cookies may be used for this purpose. Cookies are text files that are stored locally in the cache of the website visitor’s web browser. Cookies enable the web browser to be recognised.
Eye-Able Accessibility
Eye-Able® is software developed by Web Inclusion GmbH to ensure that everyone has barrier-free access to information on the internet. The files required for this, such as JavaScript, style sheets and images, are loaded from an external server. When functions are activated, Eye-Able® uses the browser’s local storage to save the settings. All settings are stored locally only and are not transmitted further. To ward off attacks and provide our service in near real time, Eye-Able® uses the Content Delivery Network (CDN) provided by BunnyWay d.o.o. (Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia). This is done for the purpose of fulfilling our contractual obligations to our customers (Article 6(1)(b) of the GDPR) and in the interests of ensuring the secure, fast and efficient provision of our online service by a professional provider (Article 6(1)(f) of the GDPR). All data transmitted and all servers remain within the EU at all times to ensure processing complies with the GDPR. Web Inclusion GmbH does not, at any time, collect or analyse personal user behaviour or other personal data. To ensure processing complies with data protection regulations, Web Inclusion GmbH has entered into data processing agreements with our hosting provider, BunnyWay. Further information can be found in the privacy policies: https://eye-able.com/datenschutz-eye-able/ https://bunny.net/privacy
Neo Commerce
I .We have integrated the Neocom guided-selling service provided by Neo Commerce GmbH (hereinafter ‘Neocom’), Max-Bill-Str. 8, 80807 Munich, onto our website to provide you with a digital, interactive product advisory service. When you start this product advice service, you can find your desired product through a quiz-like, guided process and, at the end, receive a product recommendation which you can then have sent to you by email if you wish.
II. During the consultation, Neocom collects the following browser HTTP information: browser type and version, IP address, and browser language. In addition, a session ID is generated and temporarily stored on your device during the browser session to enable us to provide the advice. The purpose is to ensure the correct and complete display and execution of the digital product advice, similar to a shopping cart function. The legal basis is our legitimate interest pursuant to Article 6(1), first sentence, point (f) of the GDPR (browser query) and Article 6(1), first sentence, point (a) of the GDPR (consent regarding the session ID).
III. Furthermore, a persistent Neocom session ID is stored. This is a purchase tracking tool used to determine whether a purchase has been made with us following the product advice – even across multiple browser sessions. However, this only takes place with your prior consent. The legal basis is therefore Article 6(1), first sentence, point (a) of the GDPR. The session ID is deleted after 365 days at the latest.
IV. Your email address is requested in order to send you product recommendations by email, should you so wish. Neocom uses this address solely for the purpose of sending you the information you have requested. However, this is only done with your prior consent. The legal basis for this is therefore Article 6(1), first sentence, point (a) of the GDPR. We use the so-called ‘double opt-in procedure’ for registration. Once you have provided your email address, we will send you an email containing a confirmation link to confirm your request to receive the product recommendation. If you click on this confirmation link, your email address will be stored for the purpose of sending the email. If you do not click on the confirmation link within 24 hours, your registration details will be blocked. You may withdraw your consent to the processing of personal data pursuant to Article 6(1), first sentence, point (a) of the GDPR at any time. If you contact us by email, you may object to the storage of your personal data at any time.
V. Neocom uses additional services for product advice. Details to these can be found here.
VI. Use of Neocom product advice within AI-based assistance systems.
It is also possible to use the Neocom product advice service via AI-supported assistance systems. In some cases, interaction takes place via free-text inputs from users. Personal information may also be transmitted in this context. Please note that the use of free-text inputs is voluntary and no sensitive information is required. These inputs are processed – to the extent technically necessary – and stored in accordance with recognised best-practice standards, where appropriate in anonymised or pseudonymised form. The data is encrypted at the access level using state-of-the-art technology (AES-256). Processing is carried out exclusively for the purpose of providing and optimising the interactive product advice. In individual cases, this may involve the transfer of data to service providers in third countries outside the EU. In such cases, we ensure that appropriate safeguards are in place in accordance with Article 44 et seq. of the GDPR. Use of the AI-based version is optional; alternatively, a fully click-based interface remains available. The legal basis is your consent in accordance with Article 6(1), first sentence, point (a) of the GDPR.
Use of Hotjar
For the purpose of website analysis, technologies provided by Hotjar Ltd., Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 3155, Malta (‘Hotjar’) are used to automatically collect and store data (IP address, time of visit, device and browser information, and information regarding your use of our website), from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. The pseudonymised usage profiles will not be merged with personal data relating to the holder of the pseudonym without your separate, explicit consent. Hotjar acts on our behalf.
use of the Vimeo video plugin to embed third-party content
To embed third-party content, data (IP address, time of visit, device and browser information) is collected via the video plugin provided by Vimeo Inc., 330 West 34th Street, 5th Floor, New York 10011, USA (“Vimeo”), data (IP address, time of visit, device and browser information) is collected, transmitted to Vimeo and subsequently processed by Vimeo. Data processing takes place on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Google Analytics is automatically integrated into the Vimeo video plugin. For the purpose of website analysis, Google Analytics automatically collects and stores data (IP address, time of visit, device and browser information, as well as information regarding your use of our website), from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. Google Analytics is a service provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by Google regarding your use of our website is generally transferred to a server operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and stored there. If you visit our website from within the EU, your IP address is stored on a server located in the EU for the purpose of deriving location data and is then immediately deleted before the traffic is forwarded to other Google servers for processing. We have no influence over or access to the data processing carried out by Vimeo, including the settings and results of Google Analytics.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
8. Integration of the Trusted Shops Trustbadge/ other widgets
Provided you have given your consent in accordance with Article 6(1)(a) of the GDPR, Trusted Shops widgets are integrated on this website to display Trusted Shops services (e.g. seals of approval, collected reviews) and to offer Trusted Shops products to buyers following an order.
The Trustbadge and the services advertised via it are provided by Trusted Shops SE, Subbelrather Str. 15C, 50823 Cologne ("Trusted Shops"), with whom we are joint data controllers under Article 26 of the GDPR. In this privacy notice, we provide you with the following information regarding the key terms of the agreement in accordance with Article 26(2) of the GDPR.
In the context of the joint responsibility between us and Trusted Shops SE, please contact Trusted Shops in the first instance regarding data protection enquiries and to exercise your rights, using the contact details provided in their privacy policy. Regardless of this, you may always contact the data controller of your choice. Your enquiry will then, if necessary, be forwarded to the other data controller for a response.
8.1 Data processing when the Trustbadge/ other widgets are integrated
The Trustbadge is provided by a US-based CDN (Content-Delivery-Network) provider. An adequate level of data protection is ensured in each case by an adequacy decision of the European Commission, which can be accessed here for the USA. Service providers based in the USA are generally certified under the EU-US Data Privacy Framework (DPF). Further information is available here. Where service providers are not certified under the DPF, standard contractual clauses have been agreed as an appropriate safeguard.
When the Trustbadge is accessed, the web server automatically stores a so-called server log file, which also contains your IP address, the date and time of access, the volume of data transferred and the requesting provider (access data), and documents the access. The IP address is anonymised immediately after collection, so that the stored data cannot be linked to you personally. The anonymised data is used in particular for statistical purposes and for error analysis.
8.2 Data processing after completion of an order
Provided you have given your consent, once the order has been completed, the Trustbadge will access the order information stored on your device (order total, order number, product purchased, if applicable) as well as your email address and your email address is hashed using a cryptographic one-way function. The hash value is then transmitted to Trusted Shops together with the order information in accordance with Article 6(1), first sentence, point (a) of the GDPR.
This serves to check whether you are already registered for Trusted Shops’ services. If this is the case, further processing takes place in accordance with the contractual agreement between you and Trusted Shops. If you are not yet registered for the services or do not give your consent to automatic recognition via the Trustbadge, you will subsequently be given the option to register manually to use the services or to finalise the agreement under your existing user contract, if applicable.
For this purpose, once you have completed your order, the Trustbadge accesses the following information stored on the device you are using: order total, order number and email address. This is necessary so that we can offer you buyer protection. The data will only be transmitted to Trusted Shops once you have actively opted to take out buyer protection by clicking on the button labelled accordingly in the so-called Trustcard. If you decide to use the services, further processing is governed by the contractual agreement with Trusted Shops in accordance with Article 6(1)(b) of the GDPR, in order to complete your registration for buyer protection, to secure the order and, where applicable, to subsequently send you review invitations by email.
Trusted Shops uses service providers in the areas of hosting, monitoring and logging. The legal basis is Article 6(1)(f) of the GDPR for the purpose of ensuring trouble-free operation. In doing so, processing may take place in third countries (the USA, Great Britain and Israel). An adequate level of data protection is ensured in each case by an adequacy decision of the European Commission, which is available here for the USA, here for Great Britain and here for Israel. Service providers based in the USA are generally certified under the EU-US Data Privacy Framework (DPF). Further information is available here. Where service providers are not certified under the DPF, standard contractual clauses have been agreed as an appropriate safeguard.
9. Social media
9.1 Social buttons from Facebook (by Meta) and Instagram (by Meta)
Our website uses social media buttons from social networks. These are merely embedded in the page as HTML links, so that no connection is established with the servers of the respective provider when you visit our website. If you click on one of the buttons, the website of the relevant social network will open in a new window in your browser There, you can, for example, click the ‘Like’ or ‘Share’ button.
9.2 Our online presence on Facebook (by Meta), Instagram (by Meta), YouTube, Pinterest, LinkedIn and Xing
Insofar as you have given your consent to the relevant social media operator in accordance with Article 6(1)(a) of the GDPR, when you visit our online presences on the social media platforms listed above, your data will be automatically collected and stored for market research and advertising purposes, from which usage profiles are created using pseudonyms. These may be used, for example, to display adverts on and off the platforms that are presumed to match your interests. Cookies are generally used for this purpose. For detailed information on the processing and use of data by the respective social media provider, as well as contact details, your rights in this regard and settings to protect your privacy, please refer to the providers’ privacy policies linked below. Should you nevertheless require assistance in this matter, please do not hesitate to contact us.
Facebook (by Meta) is a service provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Meta Platforms Ireland”). The information automatically collected by Meta Platforms Ireland regarding your use of our online presence on Facebook (by Meta) is generally transferred to and stored on a server belonging to Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Data processing in connection with a visit to a Facebook (by Meta) fan page is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Further information (regarding Insights data) can be found here.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has determined, by means of a decision, that an adequate level of data protection exists: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been granted.
Our service providers are based in and/or use servers in the following countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil and Mexico.
There is no adequacy decision from the European Commission for these countries. Our cooperation with them is based on these safeguards: Standard Data Protection Clauses of the European Commission.
Instagram (by Meta) is a service provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Meta Platforms Ireland”). The information automatically collected by Meta Platforms Ireland regarding your use of our online presence on Instagram is generally transferred to a server operated by Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA, Menlo Park, California 94025, USA, and stored there. Data processing in connection with a visit to an Instagram (by Meta) fan page is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Further information (information on Insights data) can be found here.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has determined, by means of a decision, that an adequate level of data protection exists: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been granted.
Our service providers are based in and/or use servers in the following countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil and Mexico.
There is no adequacy decision by the European Commission for these countries. Our cooperation with you is based on these safeguards: the European Commission’s Standard Data Protection Clauses.
YouTube is a service provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by Google regarding your use of our online presence on YouTube is generally transmitted to and stored on a server operated by Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
Pinterest is a service provided by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland (“Pinterest”). The information automatically collected by Pinterest regarding your use of our online presence on Pinterest is generally transmitted to and stored on a server operated by Pinterest, Inc., 505 Brannan St., San Francisco, CA 94107, USA.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
LinkedIn is a service provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”). The information automatically collected by LinkedIn regarding your use of our online presence on LinkedIn is generally transmitted to and stored on a server belonging to LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined that an adequate level of data protection exists: USA.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been granted.
Xing is a service provided by New Work SE, Am Strandkai 1, 20457 Hamburg, Germany.
10. How to contact us and your rights
10.1 Your rights
As a data subject, you have the following rights:
- in accordance with Article 15 of the GDPR, the right to request information, to the extent specified therein, regarding your personal data processed by us;
- in accordance with Article 16 of the GDPR, the right to request, without undue delay, the rectification of inaccurate personal data or the completion of your personal data stored by us;
- In accordance with Article 17 of the GDPR, you have the right to request the erasure of your personal data stored by us, provided that further processing
- to exercise the right to freedom of expression and information;
- to comply with a legal obligation;
- for reasons of public interest or
- is necessary for the assertion, exercise or defence of legal claims;
- in accordance with Article 18 of the GDPR, you have the right to request the restriction of the processing of your personal data, insofar as
- you dispute the accuracy of the data;
- the processing is unlawful, but you object to its erasure;
- we no longer require the data, but you require it to establish, exercise or defend legal claims, or
- you have lodged an objection to the processing in accordance with Article 21 of the GDPR;
- in accordance with Article 20 of the GDPR, the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transferred to another controller;
- in accordance with Article 77 of the GDPR, the right to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority for your usual place of residence, your place of work or our company’s registered office.
| Right to object Where we process personal data as explained above in order to safeguard our legitimate interests, which prevail following a balancing of interests, you may object to this processing with effect for the future. If the processing is carried out for direct marketing purposes, you may exercise this right at any time as described above. Where the processing is carried out for other purposes, you have a right to object only if there are grounds arising from your particular situation. Once you have exercised your right to object, we will no longer process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or where the processing serves to establish, exercise or defend legal claims. This does not apply if the processing is carried out for direct marketing purposes. In that case, we will no longer process your personal data for this purpose. |
10.2 Contact details
If you have any questions regarding the collection, processing or use of your personal data, or if you wish to request information, rectification, restriction or erasure of data, or to withdraw your consent or object to a specific use of your data, please contact us directly using the contact details provided in our legal notice.
Data Protection Officer:
SHIELD GmbH Martin Vogel
Ohlrattweg 5
25497 Prisdorf
Germany
info@shield-datenschutz.de
Privacy Policy
Hosting
2. Data processing for the fulfilment of contracts and for establishing contact
2.1 Data processing for the fulfilment of contracts
2.2 Customer account
2.3 Microsoft 365, including Outlook and Microsoft 365 Copilot
2.4 Contacting us
3. Data processing for the purpose of order fulfilment
Disclosure of data to delivery service providers for the purpose of delivery notifications
4. Data processing for payment processing
4.1 Data processing for transaction processing
4.2 Data processing for the purposes of fraud prevention and optimising our payment processes
4.3 Identity and credit checks when selecting Klarna payment services
5. Advertising by email
5.1 EmailNewsletter with login details, Newsletter tracking with separate consent
5.2 Newsletter distribution
5.3 Sending requests for reviews by email
6. Cookies and other technologies
6.1 General information
6.2 Consent Manager Platform (CMP)
6.3 Information on transfers to third countries (data transfers to third countries)
7. Use of cookies and other technologies
7.1 Use of Google services
7.2 Use of Facebook services
7.3 Other providers of web analytics and online marketing services
8. Integration of the Trusted Shops Trustbadge/other widgets
8.1 Data processing when the Trustbadge or other widgets are integrated
8.2 Data processing after completion of an order
9. Social media
9.1 Social media buttons for Facebook (by Meta) and Instagram (by Meta)
9.2 Our online presence on Facebook (by Meta), Instagram (by Meta), YouTube, Pinterest, LinkedIn and Xing
10. Contact details and your rights
10.1 Your rights
10.2 Contact details
The data controller is:
travelite GmbH + Co. KG
Merkurring 70-72
22143 Hamburg
Email: info@travelite.de
We appreciate your interest in our online shop. Protecting your privacy is very important to us. Below, we provide detailed information on how we handle your data.
1. Access data and hosting
You may visit our web pages without providing any personal information. Each time a web page is accessed, the web server automatically stores a so-called server log file, which contains, for example, the name of the file requested, your IP address, the date and time of the request, the volume of data transferred and the requesting provider (access data), and documents the request. This access data is analysed solely for the purpose of ensuring the smooth operation of the site and improving our service. This serves to safeguard our legitimate interests, which prevail following a balancing of interests, in the correct presentation of our services in accordance with Article 6(1)(f) of the GDPR. All access data is deleted no later than seven days after the end of your visit to the site.
Hosting
The services relating to the hosting and display of the website are partly provided by our service providers as part of data processing on our behalf. Unless otherwise stated in this privacy policy, all access data and all data collected via the forms provided for this purpose on this website are processed on their servers. If you have any questions regarding our service providers and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has determined, by means of a decision, that an adequate level of data protection exists: the United Kingdom, Canada and the USA.
There is a decision by the European Commission on an adequate level of data protection for the USA as the basis for a transfer to a third country, provided that the relevant service provider is certified. Pending certification by our service providers, data transfers will continue to be based on the following: the European Commission’s Standard Data Protection Clauses
Our service providers are based in and/or use servers in the following countries: Australia.
There is no adequacy decision by the European Commission for these countries. Our cooperation with you is based on these safeguards: the European Commission’s Standard Data Protection Clauses.
2. Data processing for contract fulfilment and for establishing contact
2.1 Data processing for the performance of a contract
For the purpose of contract fulfilment (including enquiries regarding and the handling of any existing warranty claims and claims for breach of contract, as well as any statutory obligations to provide updates) in accordance with Article 6(1)(b) of the GDPR, we collect personal data if you voluntarily provide it to us as part of your order. Mandatory fields are marked as such, as in these cases we absolutely require the data for the performance of the contract and cannot dispatch the order without it. The data collected is specified in the relevant input forms.
Further information on the processing of your data, in particular regarding its disclosure to our service providers for the purposes of order processing, payment processing and dispatch, can be found in the following sections of this privacy policy. Once the contract has been fully fulfilled, your data will be restricted for further processing and deleted upon expiry of the retention periods under tax and commercial law in accordance with Article 6(1), first sentence, point (c) of the GDPR, unless you have expressly consented to the further use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy.
Merchandise management system
We use external service providers’ merchandise management systems for order and contract processing. Our service providers act on our behalf within the framework of data processing on our behalf. If you have any questions regarding our service providers or the basis of our cooperation with them, please use the contact details provided in this privacy policy.
2.2 Customer account
Insofar as you have given your consent to this in accordance with Article 6(1)(a) of the GDPR by choosing to open a customer account, we will use your data for the purpose of opening the customer account and for storing your data for future orders on our website. You may delete your customer account at any time, either by contacting us via the contact details provided in this privacy policy or by using the function provided for this purpose within your customer account. Once your customer account has been deleted, your data will be deleted, unless you have expressly consented to the continued use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy.
2.3 Microsoft 365, including Outlook and Microsoft 365 Copilot
We use ‘Microsoft 365’, including Outlook and Microsoft 365 Copilot. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (hereinafter referred to as ‘Microsoft’).
Microsoft 365 is a platform for communication, collaboration, appointment management, file storage, document editing and the organisation of business processes. When using Microsoft 365, the following data in particular may be processed: master data, contact details, communication data, content data, email data, file and document content, appointment and calendar data, contract data, usage data, technical data and metadata. When using Outlook, the following data in particular may be processed: names, email addresses, email content, email attachments, subject lines, send and receive times, and other communication metadata.
We also use Microsoft 365 Copilot to support our work with Microsoft 365. Depending on usage, configuration and the authorisation scheme, Microsoft 365 Copilot may process content from Microsoft 365. This may include, in particular, emails, calendar information, contacts, files, document content, meeting content, chat and communication data, as well as other information from Microsoft 365. This processing is carried out, in particular, for the purposes of searching for information, summarising content, creating and revising texts, preparing work processes and supporting internal organisation. Microsoft 365 Copilot processes content within the scope of the authorised access policy that has been set up and, in principle, can only take into account content to which the respective user is authorised to access.
The processing of personal data may also take place in third countries, in particular in the USA. This may be the case, in particular, for support services, security and error analyses, telemetry, the use of sub-processors or, depending on the configuration of individual Microsoft services. In the case of Microsoft 365 Copilot, depending on settings and the availability of features, individual processing operations – in particular processing by large language models – may also take place outside the EU Data Boundary. In this regard, Microsoft describes the option of so-called ‘Flex Routing’ for EU and EFTA customers, whereby LLM inference may take place outside the EU Data Boundary under certain conditions.
Where personal data is transferred to Microsoft in the USA or processed there, Microsoft bases the data transfer to the USA on the European Commission’s EU-US Data Privacy Framework. Where Microsoft transfers personal data to other third countries or has it processed by sub-processors in other third countries, Microsoft states that it additionally bases these transfers on appropriate safeguards, in particular standard contractual clauses within the meaning of Article 46 of the GDPR.
Where processing is necessary for the implementation of pre-contractual measures or a contract with you, it is carried out on the basis of Article 6(1)(b) of the GDPR. Where processing is carried out to safeguard our legitimate interests, it is carried out on the basis of Article 6(1)(f) of the GDPR. Our legitimate interests lie in efficient communication, the secure organisation of our business processes, structured collaboration, the documentation of business transactions, the handling of enquiries, and supporting our employees in carrying out their business tasks. Where we are legally obliged to retain certain communications, documents or business transactions, the processing is carried out on the basis of Article 6(1)(c) of the GDPR. Where special categories of personal data are processed in individual cases, this will only take place if there is a legal basis for doing so in accordance with Article 9 of the GDPR.
Microsoft processes personal data, insofar as this processing is carried out on our behalf for the provision and operation of Microsoft 365, including Outlook and Microsoft 365 Copilot, as a data processor within the meaning of Article 4(8) of the GDPR. We have entered into a data processing agreement with Microsoft within the meaning of Article 28(3) of the GDPR. In this agreement, Microsoft undertakes, in particular, to process personal data only in accordance with our instructions and for the purpose of providing the agreed services, to implement appropriate technical and organisational safeguards, and to engage sub-processors only in accordance with the contractual provisions.
Further information on data processing by Microsoft can be found at https://www.microsoft.com/de-de/privacy/privacystatement . Further information on the Microsoft Products and Services Data Protection Addendum can be found at https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA
2.4 Contacting us
As part of our customer communications, we collect personal data to process your enquiries in accordance with Article 6(1)(b) of the GDPR if you voluntarily provide this to us when contacting us (e.g. via the contact form, live chat tool or email). Mandatory fields are marked as such, as we require this data in these cases to process your enquiry. The data collected is specified in the relevant input forms. Once your enquiry has been fully processed, your data will be deleted, unless you have expressly consented to the further processing of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy.
3. Data processing for the purpose of order fulfilment
To fulfil the contract in accordance with Article 6(1)(b) of the GDPR, we pass on your data to the delivery service provider commissioned to carry out the delivery, insofar as this is necessary for the delivery of the goods ordered. If you have any questions regarding our service providers and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
Disclosure of data to delivery service providers for the purpose of delivery notifications
Provided you have given us your explicit consent to this during or after placing your order, we will, on this basis and in accordance with Article 6(1)(a) of the GDPR, pass on your email address to the selected delivery service provider, so that they can contact you prior to delivery to notify you of the delivery or to arrange a suitable time.
Consent may be withdrawn at any time by sending a message via the contact details provided in this privacy policy or directly to the delivery service provider at the contact address listed below. Following revocation, we will delete the data you have provided for this purpose, unless you have expressly consented to the continued use of your data or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy. If you have any questions regarding our service providers and the basis of our cooperation with them, please contact us using the contact details provided in this privacy policy.
DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Germany
DPD Deutschland GmbH
Wailandtstraße 1
63741 Aschaffenburg
Germany
4. Data processing for payment processing
We work with the following partners to process payments in our online shop: technical service providers, banks and payment service providers.
4.1 Data processing for transaction processing
Depending on the selected payment method, we pass on the data necessary for processing the payment transaction to our technical service providers, who act on our behalf as data processors, or to the designated credit institutions or the selected payment service provider, insofar as this is necessary to process the payment. This serves to fulfil the contract in accordance with Article 6(1), first sentence, point (b) of the GDPR. In some cases, the payment service providers collect the data required to process the payment themselves, e.g. on their own website or via a technical integration into the ordering process. In this respect, the privacy policy of the respective payment service provider applies.
If you have any questions regarding our payment processing partners and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
4.2 Data processing for the purposes of fraud prevention and optimising our payment processes
Where necessary, we may provide our service providers with further data, which they use – together with the data required to process payments – in their capacity as our data processors for the purposes of fraud prevention and optimising our payment processes (e.g. invoicing, handling disputed payments, supporting our accounts department). In accordance with Article 6(1), first sentence, point (f) of the GDPR, this serves to safeguard our legitimate interests – which, following a balancing of interests, are deemed to prevail – in protecting ourselves against fraud and in ensuring efficient payment management.
4.3 Identity and credit checks when selecting Klarna payment services
Purchase on account via Klarna
If you choose to use the payment services provided by Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter ‘Klarna’), we ask for your consent pursuant to Article 6(1)(a) of the GDPR to allow us to transfer to Klarna the data necessary for processing the payment and for carrying out an identity and credit check. In Germany, the credit reference agencies listed in Klarna’s privacy policy may be used for identity and credit checks. Klarna uses the information received regarding the statistical probability of payment default to make a balanced decision on whether to establish, continue or terminate the contractual relationship. You may withdraw your consent at any time by contacting us via the contact details provided in this privacy policy. This may mean that we are no longer able to offer you certain payment options. You may also withdraw your consent to this use of personal data at any time by contacting Klarna directly.
5. Advertising by email
5.1 EmailNewsletter with registration, Newsletter tracking with separate consent
If you subscribe to our ‘ Newsletter ’, we use the data required for this purpose or provided separately by you to send you our regular ‘E-Mail-Newsletter ’ on the basis of your consent in accordance with Article 6(1), first sentence, point (a) of the GDPR. You can unsubscribe from Newsletter at any time, either by contacting us via the method described below or by using the link provided for this purpose at Newsletter. Once you have unsubscribed, we will remove your email address from the mailing list, unless you have expressly consented to the further processing of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to process your data for other purposes that are permitted by law and about which we inform you in this notice.
If you have also given us your consent in accordance with Article 6(1)(a) of the GDPR to analyse our Newsletter, we will also analyse your interaction with our Newsletter by measuring, storing and evaluating open rates and click-through rates for the purpose of designing future newsletter campaigns (“Newsletter tracking”).
For the purposes of this analysis, the emails sent contain single-pixel technologies (e.g. so-called web beacons, tracking pixels) which are stored on our website. For the purposes of analysis, we link the following ‘newsletter data’
- the page from which the page was requested (known as the referrer URL),
- the date and time of the visit,
- a description of the type of web browser used,
- the IP address of the requesting computer,
- the email address,
- the date and time of registration and confirmation
and the one-pixel technologies with your email address or your IP address and, where applicable, an individual ID. Links contained within the Newsletter may also contain this ID.
You can opt out of Newsletter tracking at any time, either by sending a message via the contact details provided or by using the link provided for this purpose on Newsletter.
The information will be stored for as long as you remain a subscriber to the Newsletter.
5.2 Newsletter distribution
Newsletter and the Newsletter tracking shown above may also be sent by our service providers as part of processing carried out on our behalf. If you have any questions regarding our service providers and the basis of our cooperation with them, please contact us using the contact details provided in this privacy policy.
5.3 Sending requests for reviews by email
Provided that you have given us your explicit consent in accordance with Article 6(1)(a) of the GDPR during or after placing your order, we will use your email address to request that you submit a review of your order via the review system we use. This consent may be withdrawn at any time by sending a message via the contact details provided in this privacy policy or via a link provided for this purpose in the review request. Once you have withdrawn your consent, we will delete your email address from the recipient list, provided that you have not expressly consented to the further processing of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to process your data for other purposes that are permitted by law and about which we inform you in this policy.
Review requests may also be sent by our service provider, Trusted Shops SE, Subbelrather Str. 15C, 50823 Cologne ("Trusted Shops").
In the course of sending review requests, we receive information from Trusted Shops regarding the respective status (e.g. whether the review request has been sent and whether it has been received). This is carried out in accordance with Article 6(1)(f) of the GDPR to fulfil our legitimate interest in receiving information about the review invitations, so that we may, where necessary, as well as to fulfil Trusted Shops’ legitimate interest in being able to offer this service.
We are jointly responsible with Trusted Shops for sending requests for reviews and for collecting and displaying review and status information.
In the context of the joint controllership arrangement between us and Trusted Shops, please contact Trusted Shops in the first instance regarding data protection enquiries and to exercise your rights; their contact details can be found here. Further information on data protection can be found via the following link here. Irrespective of this, you may also contact us at any time using the contact details provided in this privacy policy. Your enquiry will then, if necessary, be forwarded to the other data controller for a response.
6. Cookies and other technologies
6.1 General information
To make your visit to our website more engaging and to enable the use of certain functions, we use various technologies on different pages, including so-called cookies. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted at the end of the browser session, i.e. when you close your browser (so-called session cookies). Other cookies remain on your device and enable us to recognise your browser the next time you visit (persistent cookies). You can find the storage duration in the overview within your web browser’s cookie settings.
Privacy protection on end devices
When you use our online services, we employ technologies that are strictly necessary to provide the explicitly requested telemedia service. The storage of information on your device or access to information already stored on your device does not require your consent in this respect.
For functions that are not strictly necessary, the storage of information on your device or access to information already stored on your device requires your consent. Please note that if you do not give your consent, parts of the website may not be fully accessible. Any consent you have given will remain valid until you adjust or reset the relevant settings on your device.
Any subsequent data processing carried out by cookies and other technologies
We use technologies that are strictly necessary for the use of certain functions on our website (e.g. the shopping basket function). These technologies collect and process your IP address, the time of your visit, device and browser information, and details of your use of our website (e.g. information regarding the contents of your shopping basket). This is based on a balancing of interests, where our overriding legitimate interests in optimising the presentation of our services prevail, in accordance with Article 6(1), first sentence, point (f) of the GDPR.
We also use technologies to fulfil the legal obligations to which we are subject (e.g. to be able to demonstrate consent to the processing of your personal data) as well as for web analytics and online marketing. Further information on this, including the respective legal basis for data processing, can be found in the following sections of this privacy policy.
Cookie settings
You can find the cookie settings for your browser via the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™
Where you have consented to the use of these technologies in accordance with Article 6(1), first sentence, point (a) of the GDPR, you may withdraw your consent at any time by sending a message via the contact details provided in this privacy policy. Alternatively, you can also visit the following link: https://www.travelite.com/de. If you do not accept cookies, the functionality of our website may be restricted.
6.2 Consent Manager Platform (CMP)
On our website, we use a consent management service (‘Consent Manager Platform (CMP)’) to inform you about the cookies and other technologies we use on our website, and to obtain, manage and document your consent – where required – to the processing of your personal data by these technologies. This is necessary in accordance with Article 6(1), first sentence, point (c) of the GDPR to fulfil our legal obligation under Article 7(1) of the GDPR to be able to demonstrate your consent to the processing of your personal data, to which we are subject. The Consent Manager Platform (CMP) used is a service provided by ACRIS E-Commerce GmbH, Am Pfenningberg 60, 4040 Linz, Austria, which processes your data on our behalf.
Once you have submitted your cookie consent on our website, the web server stores the following data: IP address, device information, browser information, language setting, the webpage accessed or its URL, the date and time of your declaration of consent, and information regarding your consent behaviour.
In addition, the following technologies are used, which contain information regarding your consent behaviour: Cookies
The data is stored exclusively on your device; no personal data is transferred to the provider of the Consent Manager Platform (CMP). Your data will be deleted after 30 days, unless you have expressly consented to the further use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data beyond this, provided such use is permitted by law and we inform you of this in this policy.
6.3 Information on transfers to third countries (data transfers to third countries)
We use technologies from service providers on our website whose registered offices and/or server locations may be situated in third countries, outside the EU or the EEA. If there is no adequacy decision by the European Commission for that country, an adequate level of data protection must be ensured by means of other suitable safeguards.
Appropriate safeguards in the form of contractually agreed standard contractual clauses issued by the European Commission or binding corporate rules (BCRs) are, in principle, possible; however, they require prior review by the contracting parties to determine whether an adequate level of protection can be guaranteed. According to the case law of the European Court of Justice, it may be necessary to implement additional safeguards for this purpose.
We have, as a matter of principle, agreed to the Standard Data Protection Clauses issued by the European Commission with the technology providers we use who process personal data in a third country. Where possible, we also agree on additional safeguards designed to ensure that an adequate level of data protection is guaranteed in third countries without an adequacy decision.
Notwithstanding this, it may be the case that, despite all contractual and technical measures, the level of data protection in the third country does not correspond to that of the EU. In such cases, we ask you, where necessary, as part of the cookie consent process, to give your consent in accordance with Article 49(1)(a) of the GDPR to the transfer of your personal data to a third country.
In particular, there is a risk that local authorities in the third country may, from a European data protection perspective, be granted access rights to your personal data that are not sufficiently restricted, that we, as the data exporter, or you, as the data subject, may not be aware of this, and/or that you may not have sufficient legal remedies available to prevent this and/or to take action against such access.
In particular, the following countries are currently classified as third countries without an adequacy decision by the European Commission (exemplary list):
- China
- Russia
- Taiwan
You can find out to which third countries we transfer data in the privacy notices for the respective tool and/or the consent management service we use (Consent Manager Platform, CMP).
7. Use of cookies and other technologies
We use the following cookies and other third-party technologies on our website. Unless otherwise stated for the individual technologies, this is done on the basis of your consent in accordance with Article 6(1)(a) of the GDPR. Once the purpose has ceased to apply and we have stopped using the relevant technology, the data collected in this context will be deleted. You may withdraw your consent at any time with effect for the future. Further information on how to withdraw your consent can be found in the section "Cookies and other technologies". Further information, including the legal basis for our cooperation with the individual providers, can be found in the sections on the individual technologies. If you have any questions regarding the providers and the legal basis for our cooperation with them, please use the contact details provided in this privacy policy.
7.1 Use of Google services
We use the technologies described below provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (‘Google’). The information automatically collected by Google’s technologies regarding your use of our website is generally transmitted to a server operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and stored there. Unless otherwise specified for individual technologies, data processing is carried out on the basis of an agreement concluded between joint controllers for the respective technology in accordance with Article 26 of the GDPR. Further information on data processing by Google can be found in the Google’s privacy policy.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
Google Analytics
For the purpose of website analysis, data (IP address, time of visit, device and browser information, and information regarding your use of our website) is automatically collected and stored using Google Analytics; this data is used to create usage profiles using pseudonyms. Cookies may be used for this purpose. If you visit our website from within the EU, your IP address is stored on a server located in the EU for the purpose of deriving location data and is then immediately deleted before the traffic is forwarded to other Google servers for processing. Data processing is carried out on the basis of a data processing agreement with Google.
If you us do not give in accordance with Article 6(1)(a) of the GDPR for the use of Google Analytics, no cookies will be stored on or read from your device. The data processing described in the preceding paragraphs will not take place. To fill gaps in web analytics through behavioural and conversion modelling, pings containing data (user agent, information on your consent behaviour, screen resolution, IP address) are sent to Google.
Google Ads
For advertising purposes in Google search results and on third-party websites, the so-called Google remarketing cookie is set; this automatically enables interest-based advertising through the collection and processing of data (IP address, time of visit, device and browser information, and information about your use of our website), using a pseudonymous cookie ID and based on the pages you have visited. Any further data processing only takes place if you have enabled the ‘personalised advertising’ setting in your Google account. In this case, if you are logged into Google whilst visiting our website, Google will use your data in conjunction with Google Analytics data to create and define audience lists for cross-device remarketing.
For website analysis and event tracking, we use Google Ads Conversion Tracking to track your subsequent usage behaviour if you have arrived at our website via a Google Ads advert. To this end, cookies may be used and data (IP address, time of visit, device and browser information, as well as information about your use of our website based on events specified by us, such as visiting a web page or subscribing to a newsletter) may be collected, from which usage profiles are created using pseudonyms.
If you do not do not give us in accordance with Article 6(1)(a) of the GDPR for the use of Google Ads, no cookies will be stored on or read from your device. The data processing described in the preceding paragraphs will not take place. To fill gaps in web analytics through behavioural and conversion modelling, pings containing data (user agent, information on your consent behaviour, screen resolution, IP address, page URL, information on ad clicks in URL parameters) are sent to Google. Your IP address is used to determine the country of origin.
Google Maps
For the visual display of geographical information, Google Maps collects data relating to your use of the Maps functions – in particular your IP address and location data – which is transmitted to Google and subsequently processed by Google. We have no influence over this subsequent data processing.
Google reCAPTCHA
To protect against misuse of our web forms and spam generated by automated software (so-called ‘bots’), Google reCAPTCHA collects data (IP address, time of visit, browser information and details of your use of our website) and analyses your use of our website using JavaScript and cookies. In addition, other cookies stored in your browser by Google services are analysed. No personal data is read or stored from the input fields of the respective form.
Google Fonts
To ensure consistent presentation of content on our website, the ‘Google Fonts’ script code collects data (IP address, time of visit, device and browser information), which is transmitted to Google and subsequently processed by Google. We have no influence over this subsequent data processing.
Google Tag Manager
Google Tag Manager enables us to manage various codes and services on our website. When implementing individual tags, Google may also process personal data (e.g. IP address, online identifiers (including cookies)). Data processing is carried out on the basis of a data processing agreement with Google.
The use of Google Tag Manager enables the integration of various services and technologies.
If you do not wish to use certain tracking services and have therefore disabled them, this deactivation will apply to all relevant tracking tags integrated via Google Tag Manager.
YouTube Video Plugin
When embedding third-party content via the YouTube video plugin in the enhanced data protection mode we use, data (IP address, time of visit, device and browser information) is collected, transmitted to Google and subsequently processed by Google only if you play a video.
7.2 Use of Facebook services
Use of Facebook Pixel
We use the Facebook Pixel as part of the technologies described below from Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (‘Facebook (by Meta)’ or ‘Meta Platforms Ireland’). The Facebook Pixel automatically collects and stores data (IP address, time of visit, device and browser information, as well as information about your use of our website based on events specified by us, such as visiting a webpage or subscribing to a newsletter), from which usage profiles are created using pseudonyms.
As part of what is known as ‘extended data matching’, information that can be used to identify individuals (e.g. names, email addresses and telephone numbers) is also collected and stored in hashed form for matching purposes.
To this end, when you visit our website, the Facebook Pixel automatically sets a cookie which, by means of a pseudonymous cookie ID, enables your browser to be recognised automatically when you visit other websites. Facebook (by Meta) will combine this information with other data from your Facebook account and use it to compile reports on website activity and to provide other services related to website usage, in particular personalised and group-based advertising.
The information automatically collected by Facebook (by Meta) technologies regarding your use of our website is generally transferred to and stored on a server operated by Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Further information on data processing by Facebook can be found in the Facebook’s (by Meta) privacy policy.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined an adequate level of data protection: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.
The adequacy decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been obtained.
Our service providers are based in and/or use servers in the following countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil and Mexico. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the following safeguards: the European Commission’s Standard Data Protection Clauses.
Facebook Analytics
As part of the Facebook Business tools, statistics on visitor activity on our website are compiled from the data collected via the Facebook Pixel regarding your use of our website. Data processing is carried out on the basis of a data processing agreement with Facebook (by Meta). The analysis is used to optimise the presentation and marketing of our website.
Facebook Ads (Ads Manager)
We use Facebook Ads to advertise this website on Facebook (by Meta) and on other platforms. We determine the parameters of the respective advertising campaign. Facebook (by Meta) is responsible for the precise implementation, in particular the decision on the placement of adverts for individual users. Unless otherwise specified for the individual technologies, data processing takes place on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Joint controllership is limited to the collection of data and its transfer to Meta Platforms Ireland. Subsequent data processing by Meta Platforms Ireland is not covered by this.
Based on the statistics generated via Facebook Pixel regarding visitor activity on our website, we operate a Custom Audience to run group-based advertising on Facebook (by Meta), by defining the characteristics of the respective target audience. As part of the extended data matching process carried out to determine the respective target audience (see above), Facebook (by Meta) acts as our data processor.
Based on the pseudonymous cookie ID set by the Facebook Pixel and the data collected about your usage behaviour on our website, we use the Facebook Pixel to carry out remarketing personalised advertising.
About Facebook Pixel Conversions we use to analyse your subsequent usage behaviour for web analytics and event tracking when you have arrived at our website via a Facebook Ads advertisement. Data processing is carried out on the basis of a data processing agreement with Facebook (by Meta).
7.3 Other providers of web analytics and online marketing services
use of AdCell retargeting for online marketing
use of AdCell retargeting for online marketing Through our advertising partner Firstlead GmbH, Rosenfelder Str. 15–16, 10315 Berlin (“adcell”), we advertise this website in search results and on third-party websites. When you visit our website, a retargeting cookie is automatically set by adcell or its partners; this enables interest-based advertising using a pseudonymous cookie ID and based on the pages you have visited. Data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. We determine the parameters of the respective advertising campaign. adcell is responsible for the precise implementation (e.g. deciding on the placement of individual adverts). The data automatically collected by adcell (IP address, time of visit, device and browser information, and information about your use of our website) may be combined by adcell with information from other sources and transmitted to adcell’s advertising partners.
Customa
On this website, data is collected and stored using technologies from customa for marketing and optimisation purposes. The provider of this technology is trust in dialog Services GmbH, Merkurring 33-35, 22143 Hamburg, https://www.customa.de. Cookies may be used for this purpose. Cookies are text files that are stored locally in the cache of the website visitor’s web browser. Cookies enable the web browser to be recognised.
Eye-Able Accessibility
Eye-Able® is software developed by Web Inclusion GmbH to ensure that everyone has barrier-free access to information on the internet. The files required for this, such as JavaScript, style sheets and images, are loaded from an external server. When functions are activated, Eye-Able® uses the browser’s local storage to save the settings. All settings are stored locally only and are not transmitted further. To ward off attacks and provide our service in near real time, Eye-Able® uses the Content Delivery Network (CDN) provided by BunnyWay d.o.o. (Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia). This is done for the purpose of fulfilling our contractual obligations to our customers (Article 6(1)(b) of the GDPR) and in the interests of ensuring the secure, fast and efficient provision of our online service by a professional provider (Article 6(1)(f) of the GDPR). All data transmitted and all servers remain within the EU at all times to ensure processing complies with the GDPR. Web Inclusion GmbH does not, at any time, collect or analyse personal user behaviour or other personal data. To ensure processing complies with data protection regulations, Web Inclusion GmbH has entered into data processing agreements with our hosting provider, BunnyWay. Further information can be found in the privacy policies: https://eye-able.com/datenschutz-eye-able/ https://bunny.net/privacy
Neo Commerce
I .We have integrated the Neocom guided-selling service provided by Neo Commerce GmbH (hereinafter ‘Neocom’), Max-Bill-Str. 8, 80807 Munich, onto our website to provide you with a digital, interactive product advisory service. When you start this product advice service, you can find your desired product through a quiz-like, guided process and, at the end, receive a product recommendation which you can then have sent to you by email if you wish.
II. During the consultation, Neocom collects the following browser HTTP information: browser type and version, IP address, and browser language. In addition, a session ID is generated and temporarily stored on your device during the browser session to enable us to provide the advice. The purpose is to ensure the correct and complete display and execution of the digital product advice, similar to a shopping cart function. The legal basis is our legitimate interest pursuant to Article 6(1), first sentence, point (f) of the GDPR (browser query) and Article 6(1), first sentence, point (a) of the GDPR (consent regarding the session ID).
III. Furthermore, a persistent Neocom session ID is stored. This is a purchase tracking tool used to determine whether a purchase has been made with us following the product advice – even across multiple browser sessions. However, this only takes place with your prior consent. The legal basis is therefore Article 6(1), first sentence, point (a) of the GDPR. The session ID is deleted after 365 days at the latest.
IV. Your email address is requested in order to send you product recommendations by email, should you so wish. Neocom uses this address solely for the purpose of sending you the information you have requested. However, this is only done with your prior consent. The legal basis for this is therefore Article 6(1), first sentence, point (a) of the GDPR. We use the so-called ‘double opt-in procedure’ for registration. Once you have provided your email address, we will send you an email containing a confirmation link to confirm your request to receive the product recommendation. If you click on this confirmation link, your email address will be stored for the purpose of sending the email. If you do not click on the confirmation link within 24 hours, your registration details will be blocked. You may withdraw your consent to the processing of personal data pursuant to Article 6(1), first sentence, point (a) of the GDPR at any time. If you contact us by email, you may object to the storage of your personal data at any time.
V. Neocom uses additional services for product advice. Details of these can be found here.
VI. Use of Neocom product advice within AI-based assistance systems.
It is also possible to use the Neocom product advice service via AI-supported assistance systems. In some cases, interaction takes place via free-text inputs from users. Personal information may also be transmitted in this context. Please note that the use of free-text inputs is voluntary and no sensitive information is required. These inputs are processed – to the extent technically necessary – and stored in accordance with recognised best-practice standards, where appropriate in anonymised or pseudonymised form. The data is encrypted at the access level using state-of-the-art technology (AES-256). Processing is carried out exclusively for the purpose of providing and optimising the interactive product advice. In individual cases, this may involve the transfer of data to service providers in third countries outside the EU. In such cases, we ensure that appropriate safeguards are in place in accordance with Article 44 et seq. of the GDPR. Use of the AI-based version is optional; alternatively, a fully click-based interface remains available. The legal basis is your consent in accordance with Article 6(1), first sentence, point (a) of the GDPR.
Use of Hotjar
For the purpose of website analysis, technologies provided by Hotjar Ltd., Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 3155, Malta (‘Hotjar’) are used to automatically collect and store data (IP address, time of visit, device and browser information, and information regarding your use of our website), from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. The pseudonymised usage profiles will not be merged with personal data relating to the holder of the pseudonym without your separate, explicit consent. Hotjar acts on our behalf.
use of the Vimeo video plugin to embed third-party content
To embed third-party content, data (IP address, time of visit, device and browser information) is collected via the video plugin provided by Vimeo Inc., 330 West 34th Street, 5th Floor, New York 10011, USA ("Vimeo"), data (IP address, time of visit, device and browser information) is collected, transmitted to Vimeo and subsequently processed by Vimeo. Data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Google Analytics is automatically integrated into the Vimeo video plugin. For the purpose of website analysis, Google Analytics automatically collects and stores data (IP address, time of visit, device and browser information, as well as information regarding your use of our website), from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. Google Analytics is a service provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (‘Google’). The information automatically collected by Google regarding your use of our website is generally transferred to a server operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and stored there. If you visit our website from within the EU, your IP address is stored on a server located in the EU for the purpose of deriving location data and is then immediately deleted before the traffic is forwarded to other Google servers for processing. We have no influence over or access to the data processing carried out by Vimeo, including the settings and results of Google Analytics.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
8. Integration of the Trusted Shops Trustbadge/ other widgets
Provided you have given your consent in accordance with Article 6(1)(a) of the GDPR, Trusted Shops widgets are integrated on this website to display Trusted Shops services (e.g. seals of approval, collected reviews) and to offer Trusted Shops products to buyers following an order.
The Trustbadge and the services advertised via it are provided by Trusted Shops SE, Subbelrather Str. 15C, 50823 Cologne ("Trusted Shops"), with whom we are joint data controllers under Article 26 of the GDPR. In this privacy notice, we provide you with the following information regarding the key terms of the agreement in accordance with Article 26(2) of the GDPR.
As part of the joint responsibility between us and Trusted Shops SE, please contact Trusted Shops in the first instance regarding data protection queries and to exercise your rights, using the contact details provided in the privacy policy indicated contact options. Regardless of this, you may always contact the data controller of your choice. Your enquiry will then, if necessary, be forwarded to the other data controller for a response.
8.1 Data processing when the Trustbadge or other widgets are integrated
The Trustbadge is provided by a US-based CDN (Content Delivery Network) provider. An adequate level of data protection is ensured in each case by an adequacy decision of the European Commission, which can be accessed here for the USA. Service providers based in the USA are generally certified under the EU-US Data Privacy Framework (DPF). Further information is available here. Where service providers are not certified under the DPF, standard contractual clauses have been agreed as a suitable safeguard.
When the Trustbadge is accessed, the web server automatically stores a so-called server log file, which also contains your IP address, the date and time of access, the volume of data transferred and the requesting provider (access data), and documents the access. The IP address is anonymised immediately after collection, so that the stored data cannot be linked to you personally. The anonymised data is used in particular for statistical purposes and for error analysis.
8.2 Data processing after completion of an order
Provided you have given your consent, once the order has been completed, the Trustbadge will access the order information stored on your device (order total, order number, product purchased, if applicable) as well as your email address and your email address is hashed using a cryptographic one-way function. The hash value is then transmitted to Trusted Shops together with the order information in accordance with Article 6(1), first sentence, point (a) of the GDPR.
This is to check whether you are already registered for Trusted Shops’ services. If this is the case, further processing will take place in accordance with the contractual agreement between you and Trusted Shops. If you are not yet registered for the services or do not give your consent to automatic recognition via the Trustbadge, you will then be given the option to register manually to use the services or to finalise the terms of your existing user agreement, if applicable.
For this purpose, once you have completed your order, the Trustbadge accesses the following information stored on the device you are using: order total, order number and email address. This is necessary so that we can offer you buyer protection. The data will only be transmitted to Trusted Shops once you have actively opted to take out buyer protection by clicking on the button labelled accordingly in the so-called Trustcard. If you decide to use the services, further processing is governed by the contractual agreement with Trusted Shops in accordance with Article 6(1)(b) of the GDPR, in order to complete your registration for buyer protection, to secure the order and, where applicable, to subsequently send you review invitations by email.
Trusted Shops uses service providers in the areas of hosting, monitoring and logging. The legal basis for this is Article 6(1)(f) of the GDPR, for the purpose of ensuring trouble-free operation. Processing may take place in third countries (the USA, the UK and Israel). An adequate level of data protection is ensured in each case by an adequacy decision of the European Commission, which can be accessed here, for the USA here and for the UK here and for Israel can be accessed. Service providers based in the USA are generally certified under the EU-US Data Privacy Framework (DPF). Further information is available here. Where service providers are not certified under the DPF, standard contractual clauses have been agreed as an appropriate safeguard.
9. Social media
9.1 Social buttons from Facebook (by Meta) and Instagram (by Meta)
Our website uses social media buttons from social networks. These are merely embedded in the page as HTML links, meaning that no connection is established with the respective provider’s servers when you visit our website. If you click on one of the buttons, the website of the relevant social network will open in a new window in your browser There, you can, for example, click the ‘Like’ or ‘Share’ button.
9.2 Our online presence on Facebook (by Meta), Instagram (by Meta), YouTube, Pinterest, LinkedIn and Xing
Insofar as you have given your consent to the relevant social media operator in accordance with Article 6(1)(a) of the GDPR, the relevant social media operator automatically collects and stores your data for market research and advertising purposes when you visit our online presences on the social media platforms listed above. Usage profiles are created from this data using pseudonyms. These may be used, for example, to display adverts on and off the platforms that are presumed to match your interests. Cookies are generally used for this purpose. For detailed information on the processing and use of data by the respective social media provider, as well as contact details, your rights in this regard and settings to protect your privacy, please refer to the providers’ privacy policies linked below. Should you nevertheless require assistance in this matter, please do not hesitate to contact us.
Facebook (by Meta) is a service provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Meta Platforms Ireland”). The information automatically collected by Meta Platforms Ireland regarding your use of our online presence on Facebook (by Meta) is generally transmitted to and stored on a server belonging to Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Data processing in connection with a visit to a Facebook (by Meta) fan page is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Further information (including details on Insights data) can be found here.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has determined, by means of a decision, that an adequate level of data protection exists: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been granted.
Our service providers are based in and/or use servers in the following countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico.
There is no adequacy decision from the European Commission for these countries. Our cooperation with them is based on these safeguards: Standard Data Protection Clauses of the European Commission.
Instagram (by Meta) is a service provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (‘Meta Platforms Ireland’). The information automatically collected by Meta Platforms Ireland regarding your use of our online presence on Instagram is generally transferred to a server operated by Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA, Menlo Park, California 94025, USA and stored there. Data processing in connection with a visit to an Instagram (by Meta) fan page is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Further information (information on Insights data) can be found here.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has determined, by means of a decision, that an adequate level of data protection exists: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been granted.
Our service providers are based in and/or use servers in the following countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico.
There is no adequacy decision by the European Commission for these countries. Our cooperation with you is based on these safeguards: the European Commission’s Standard Data Protection Clauses.
YouTube is a service provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by Google regarding your use of our online presence on YouTube is generally transmitted to and stored on a server belonging to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
Pinterest is a service provided by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland ("Pinterest"). The information automatically collected by Pinterest regarding your use of our online presence on Pinterest is generally transmitted to and stored on a server belonging to Pinterest, Inc., 505 Brannan St., San Francisco, CA 94107, USA.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
LinkedIn is a service provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (‘LinkedIn’). The information automatically collected by LinkedIn regarding your use of our online presence on LinkedIn is generally transferred to and stored on a server belonging to LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined that an adequate level of data protection exists: USA.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been granted.
Xing is a service provided by New Work SE, Am Strandkai 1, 20457 Hamburg, Germany.
10. How to contact us and your rights
10.1 Your rights
As a data subject, you have the following rights:
- in accordance with Article 15 of the GDPR, the right to request information, to the extent specified therein, regarding your personal data processed by us;
- in accordance with Article 16 of the GDPR, the right to request, without undue delay, the rectification of inaccurate personal data or the completion of your personal data stored by us;
- In accordance with Article 17 of the GDPR, you have the right to request the erasure of your personal data stored by us, provided that further processing
- to exercise the right to freedom of expression and information;
- to comply with a legal obligation;
- for reasons of public interest or
- is necessary for the assertion, exercise or defence of legal claims;
- in accordance with Article 18 of the GDPR, you have the right to request the restriction of the processing of your personal data, insofar as
- you dispute the accuracy of the data;
- the processing is unlawful, but you object to its erasure;
- we no longer require the data, but you require it to establish, exercise or defend legal claims or
- you have lodged an objection to the processing in accordance with Article 21 of the GDPR;
- in accordance with Article 20 of the GDPR, the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transferred to another controller;
- in accordance with Article 77 of the GDPR, the right to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority for your usual place of residence, your place of work or our company’s registered office.
| Right to object Where we process personal data as explained above in order to safeguard our legitimate interests, which prevail following a balancing of interests, you may object to this processing with effect for the future. If the processing is carried out for direct marketing purposes, you may exercise this right at any time as described above. Where the processing is carried out for other purposes, you have a right to object only if there are grounds arising from your particular situation. Once you have exercised your right to object, we will no longer process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or where the processing serves to establish, exercise or defend legal claims. This does not apply if the processing is carried out for direct marketing purposes. In that case, we will no longer process your personal data for this purpose. |
10.2 Contact details
If you have any questions regarding the collection, processing or use of your personal data, or if you wish to request information, rectification, restriction or erasure of data, or to withdraw your consent or object to a specific use of your data, please contact us directly using the contact details provided in our legal notice.
Data Protection Officer:
SHIELD GmbH Martin Vogel
Ohlrattweg 5
25497 Prisdorf
Germany
info@shield-datenschutz.de