Privacy Policy
Hosting
2. Data processing for contract fulfilment and for establishing contact
2.1 Data processing for the fulfilment of the contract
2.2 Customer account
2.3 Microsoft 365, including Outlook and Microsoft 365 Copilot
2.4 Contacting us
3. Data processing for the purpose of order fulfilment
Data transfer to delivery service providers for the purpose of dispatch notification
4. Data processing for payment processing
4.1 Data processing for transaction processing
4.2 Data processing for the purposes of fraud prevention and optimising our payment processes
4.3 Identity and credit checks when selecting Klarna payment services
5. Advertising by email
5.1 Email newsletter with subscription, newsletter tracking with separate consent
5.2 Newsletter distribution
5.3 Sending requests for reviews by email
6. Cookies and other technologies
6.1 General information
6.2 Consent Manager Platform (CMP)
6.3 Information on transfers to third countries (data transfers to third countries)
7. Use of cookies and other technologies
7.1 Use of Google services
7.2 Use of Facebook services
7.3 Other providers of web analytics and online marketing services
8. Integration of the Trusted Shops Trustbadge/ other widgets
8.1 Data processing when integrating the Trustbadge/ other widgets
8.2 Data processing following completion of an order
9. Social media
9.1 Social buttons from Facebook (by Meta), Instagram (by Meta)
9.2 Our online presence on Facebook (by Meta), Instagram (by Meta), YouTube, Pinterest, LinkedIn, Xing
10. Contact details and your rights
10.1 Your rights
10.2 Contact details
The data controller is:
travelite GmbH + Co. KG
Merkurring 70-72
22143 Hamburg
Email: info@travelite.de
We appreciate your interest in our online shop. Protecting your privacy is very important to us. Below, we provide detailed information on how we handle your data.
1. Access data and hosting
You can visit our websites without providing any personal details. Each time you access a webpage, the web server automatically stores a so-called server log file, which contains, for example, the name of the requested file, your IP address, the date and time of the request, the volume of data transferred and the requesting provider (access data), and documents the request. This access data is analysed solely for the purpose of ensuring the smooth operation of the website and improving our service. This serves to safeguard our legitimate interests, which prevail following a balancing of interests, in the correct presentation of our services in accordance with Article 6(1), first sentence, point (f) of the GDPR. All access data is deleted no later than seven days after the end of your visit to the site.
Hosting
The services for hosting and displaying the website are partly provided by our service providers as part of data processing on our behalf. Unless otherwise stated in this privacy policy, all access data and all data collected via the forms provided for this purpose on this website are processed on their servers. If you have any questions regarding our service providers and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined that an adequate level of data protection exists: the United Kingdom, Canada, the USA.
A decision by the European Commission on an adequate level of data protection for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Pending certification by our service providers, data transfers will continue to be based on the following: the European Commission’s Standard Data Protection Clauses
Our service providers are based in and/or use servers in the following countries: Australia.
There is no adequacy decision by the European Commission for these countries. Our cooperation with you is based on these safeguards: the European Commission’s Standard Data Protection Clauses.
2. Data processing for contract fulfilment and for establishing contact
2.1 Data processing for the fulfilment of the contract
For the purpose of contract fulfilment (including enquiries regarding and the handling of any existing warranty claims and claims for breach of contract, as well as any statutory obligations to provide updates) in accordance with Article 6(1)(b) of the GDPR, we collect personal data if you voluntarily provide it to us as part of your order. Mandatory fields are marked as such, as in these cases we absolutely require the data for the performance of the contract and cannot dispatch the order without it. The data collected is specified in the relevant input forms.
Further information on the processing of your data, in particular regarding its transfer to our service providers for the purposes of order, payment and dispatch processing, can be found in the following sections of this privacy policy. Once the contract has been fully fulfilled, your data will be restricted for further processing and deleted upon expiry of the retention periods under tax and commercial law in accordance with Article 6(1), first sentence, point (c) of the GDPR, unless you have expressly consented to the further use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data beyond this scope where such use is permitted by law and about which we inform you in this policy.
Merchandise management system
We use external service providers’ merchandise management systems for order and contract processing. Our service providers act on our behalf within the framework of data processing on our behalf. If you have any questions regarding our service providers or the basis of our cooperation with them, please use the contact details provided in this privacy policy.
2.2 Customer account
Provided that you have given your consent in accordance with Article 6(1), first sentence, point (a) of the GDPR by choosing to open a customer account, we will use your data for the purpose of opening your customer account and for storing your data for future orders on our website. You may delete your customer account at any time, either by contacting us via the contact details provided in this privacy policy or by using the function provided for this purpose within your customer account. Once your customer account has been deleted, your data will be deleted, unless you have expressly consented to the further use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy.
2.3 Microsoft 365, including Outlook and Microsoft 365 Copilot
We use “Microsoft 365”, including Outlook and Microsoft 365 Copilot. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (hereinafter referred to as “Microsoft”).
Microsoft 365 is a platform for communication, collaboration, appointment management, file storage, document editing and the organisation of business processes. When using Microsoft 365, the following data in particular may be processed: master data, contact details, communication data, content data, email data, file and document content, appointment and calendar data, contract data, usage data, technical data and metadata. When using Outlook, the following data in particular may be processed: names, email addresses, email content, email attachments, subject lines, send and receive times, and other communication metadata.
We also use Microsoft 365 Copilot to support our work with Microsoft 365. Depending on usage, configuration and the permissions model, Microsoft 365 Copilot may process content from Microsoft 365. This may include, in particular, emails, calendar information, contacts, files, document content, meeting content, chat and communication data, as well as other information from Microsoft 365. This processing is carried out, in particular, to search for information, summarise content, create and revise texts, prepare work processes and support internal organisation. Microsoft 365 Copilot processes content within the framework of the configured authorization scheme and, in principle, can only take into account content to which the respective user is authorized to access.
The processing of personal data may also take place in third countries, in particular in the USA. This may be the case, in particular, in relation to support services, security and error analyses, telemetry, the use of sub-processors or, depending on the configuration of individual Microsoft services. With Microsoft 365 Copilot, depending on settings and the availability of features, individual processing operations – in particular processing by large language models – may also take place outside the EU Data Boundary. In this regard, Microsoft describes the option of so-called ‘Flex Routing’ for EU and EFTA customers, whereby LLM inference may take place outside the EU Data Boundary under certain conditions.
Where personal data is transferred to Microsoft in the USA or processed there, Microsoft bases the data transfer to the USA on the European Commission’s EU-US Data Privacy Framework. Where Microsoft transfers personal data to other third countries or has it processed by sub-processors in other third countries, Microsoft states that it bases these transfers additionally on appropriate safeguards, in particular standard contractual clauses within the meaning of Article 46 of the GDPR.
Where processing is necessary for the implementation of pre-contractual measures or a contract with you, it is carried out on the basis of Article 6(1)(b) of the GDPR. Where processing is carried out to safeguard our legitimate interests, it is carried out on the basis of Article 6(1)(f) of the GDPR. Our legitimate interests lie in efficient communication, the secure organisation of our business processes, structured collaboration, the documentation of business transactions, the handling of enquiries, and supporting our employees in carrying out their business tasks. Where we are legally obliged to retain certain communications, documents or business transactions, the processing is carried out on the basis of Article 6(1)(c) of the GDPR. Where special categories of personal data are processed in individual cases, this is done only where there is a legal basis for doing so under Article 9 of the GDPR.
Microsoft processes personal data insofar as such processing is carried out on our behalf for the provision and operation of Microsoft 365, including Outlook and Microsoft 365 Copilot, as a data processor within the meaning of Article 4(8) of the GDPR. We have entered into a data processing agreement with Microsoft within the meaning of Article 28(3) of the GDPR. In this agreement, Microsoft undertakes, in particular, to process personal data only in accordance with our instructions and for the purpose of providing the agreed services, to implement appropriate technical and organisational safeguards, and to engage sub-processors only in accordance with the contractual provisions.
Further information on data processing by Microsoft can be found at https://www.microsoft.com/de-de/privacy/privacystatement . Further information on the Microsoft Products and Services Data Protection Addendum can be found at https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA
2.4 Contacting us
As part of our customer communications, we collect personal data to process your enquiries in accordance with Article 6(1)(b) of the GDPR if you voluntarily provide this to us when contacting us (e.g. via the contact form, live chat tool or email). Mandatory fields are marked as such, as we require this data in these cases to process your enquiry. The data collected is specified in the respective input forms. Once your enquiry has been fully processed, your data will be deleted, unless you have expressly consented to further use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy.
3. Data processing for the purpose of order fulfilment
To fulfil the contract in accordance with Article 6(1)(b) of the GDPR, we pass on your data to the delivery service provider commissioned to carry out the delivery, insofar as this is necessary for the delivery of ordered goods. If you have any questions regarding our service providers and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
Data transfer to delivery service providers for the purpose of dispatch notification
Provided you have given us your explicit consent to this during or after placing your order, we will, on this basis and in accordance with Article 6(1)(a) of the GDPR, pass on your email address to the selected delivery service provider, so that they can contact you prior to delivery to notify you of the delivery or to arrange it.
Consent may be withdrawn at any time by sending a message via the contact details provided in this privacy policy or directly to the delivery service provider at the contact address listed below. Following revocation, we will delete the data you have provided for this purpose, unless you have expressly consented to the continued use of your data or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy. If you have any questions regarding our service providers and the basis of our cooperation with them, please contact us using the contact details provided in this privacy policy.
DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Germany
DPD Deutschland GmbH
Wailandtstraße 1
63741 Aschaffenburg
Germany
4. Data processing for payment processing
We work with the following partners to process payments in our online shop: technical service providers, credit institutions and payment service providers.
4.1 Data processing for transaction processing
Depending on the selected payment method, we pass on the data necessary for processing the payment transaction to our technical service providers, who act on our behalf as data processors, or to the commissioned credit institutions or the selected payment service provider, insofar as this is necessary to process the payment. This serves to fulfil the contract in accordance with Article 6(1)(b) of the GDPR. In some cases, the payment service providers collect the data required to process the payment themselves, e.g. on their own website or via a technical integration into the ordering process. In this respect, the privacy policy of the respective payment service provider applies.
If you have any questions regarding our payment processing partners and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
4.2 Data processing for the purposes of fraud prevention and optimising our payment processes
Where necessary, we may provide our service providers with further data, which they, as our data processors, use together with the data required for payment processing for the purposes of fraud prevention and optimising our payment processes (e.g. invoicing, handling disputed payments, supporting accounting). This serves, in accordance with Article 6(1), first sentence, point (f) of the GDPR, to safeguard our legitimate interests – which, following a balancing of interests, are deemed to prevail – in protecting ourselves against fraud and in ensuring efficient payment management.
4.3 Identity and credit checks when selecting Klarna payment services
Purchase on account via Klarna
If you opt to use the payment services provided by Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter Klarna), we ask for your consent in accordance with Article 6(1)(a) of the GDPR to allow us to transfer to Klarna the data necessary for processing the payment and for carrying out an identity and creditworthiness check. In Germany, the credit reference agencies listed in Klarna’s privacy policy may be used for identity and credit checks. Klarna uses the information received regarding the statistical probability of payment default to make a balanced decision on whether to enter into, continue or terminate the contractual relationship. You may withdraw your consent at any time by contacting us via the contact details provided in this privacy policy. This may mean that we are no longer able to offer you certain payment options. You may also withdraw your consent to this use of personal data at any time by contacting Klarna directly.
5. Advertising by email
5.1 Email newsletter with subscription, newsletter tracking with separate consent
If you subscribe to our newsletter, we will use the data required for this purpose or provided separately by you to send you our email newsletter on a regular basis, based on your consent in accordance with Article 6(1), first sentence, point (a) of the GDPR. You can unsubscribe from the newsletter at any time, either by contacting us via the details provided below or by clicking on the link provided for this purpose in the newsletter. Once you have unsubscribed, we will remove your email address from the mailing list, unless you have expressly consented to the further use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy.
If you have also given us your consent in accordance with Article 6(1)(a) of the GDPR to analyse our newsletters, we will also analyse your interaction with our newsletter by measuring, storing and evaluating open rates and click-through rates for the purpose of designing future newsletter campaigns (“newsletter tracking”).
For the purposes of this analysis, the emails sent contain single-pixel technologies (e.g. so-called web beacons, tracking pixels) that are stored on our website. For the analyses, we link the following ‘newsletter data’ in particular:
- the page from which the page was requested (known as the referrer URL),
- the date and time of the visit,
- a description of the type of web browser used,
- the IP address of the requesting computer,
- the email address,
- the date and time of registration and confirmation
and the one-pixel technologies with your email address or your IP address and, where applicable, an individual ID. Links contained in the newsletter may also contain this ID.
You can unsubscribe from newsletter tracking at any time, either by sending a message via the contact details provided or by clicking on the link provided for this purpose in the newsletter.
The information will be stored for as long as you remain subscribed to the newsletter.
5.1.1 Email marketing without newsletter subscription and your right to object
If we receive your email address in connection with the sale of a product or service and you have not objected to this, we reserve the right to send you regular offers from our range. You may object to this use of your email address at any time by sending a message via the contact details provided below or via a link provided for this purpose in the promotional email, without incurring any costs other than the transmission costs in accordance with standard rates.
5.2 Newsletter distribution
The newsletter and the newsletter tracking described above may also be sent by our service providers as part of processing carried out on our behalf. If you have any questions regarding our service providers and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
5.3 Sending requests for reviews by email
Provided that you have given us your explicit consent in accordance with Article 6(1)(a) of the GDPR during or after placing your order, we will use your email address to request that you submit a review of your order via the review system we use. This consent may be withdrawn at any time by sending a message via the contact details provided in this privacy policy or via a link provided for this purpose in the review request. Once you have withdrawn your consent, we will delete your email address from the recipient list, provided that you have not expressly consented to the further processing of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to process your data for other purposes which are permitted by law and about which we inform you in this policy.
Where applicable, requests for reviews may also be sent by our service provider, Trusted Shops SE Subbelrather Str. 15C, 50823 Cologne ("Trusted Shops").
We receive information from Trusted Shops regarding the respective status in the course of sending review requests (e.g. whether the review request has been sent and whether it has been received). This is carried out in accordance with Article 6(1)(f) of the GDPR to fulfil our legitimate interest in receiving information about the review invitations, so that we can, where necessary, make optimisations on this basis, as well as to fulfil the legitimate interest of Trusted Shops in being able to offer this service.
We are jointly responsible with Trusted Shops for sending requests for reviews and for collecting and displaying review and status information.
As part of the joint responsibility between us and Trusted Shops, please contact Trusted Shops in the first instance regarding data protection queries and to exercise your rights; you can find their contact details here. Further information on data protection can be found via the following link here. Irrespective of this, you may also contact us at any time using the contact details provided in this privacy policy. Your enquiry will then, if necessary, be forwarded to the other data controller for a response.
6. Cookies and other technologies
6.1 General information
To make your visit to our website more engaging and to enable the use of certain functions, we use various technologies on different pages, including so-called cookies. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted at the end of the browser session, i.e. once you close your browser (so-called session cookies). Other cookies remain on your device and enable us to recognise your browser the next time you visit (persistent cookies). You can find the storage duration in the overview within your web browser’s cookie settings.
Privacy protection on end devices
When you use our online service, we employ technologies that are strictly necessary to provide the explicitly requested telemedia service. The storage of information on your device or access to information already stored on your device does not require your consent in this respect.
For functions that are not strictly necessary, the storage of information on your device or access to information already stored on your device requires your consent. Please note that if you do not give your consent, parts of the website may not be fully accessible. Any consent you have given will remain valid until you adjust or reset the relevant settings on your device.
Any subsequent data processing via cookies and other technologies
We use technologies that are strictly necessary for the use of certain functions on our website (e.g. the shopping basket function). These technologies collect and process your IP address, the time of your visit, device and browser information, as well as information regarding your use of our website (e.g. information about the contents of your shopping basket). This is based on a balancing of interests, where our overriding legitimate interests in optimising the presentation of our website prevail, in accordance with Article 6(1)(f) of the GDPR.
We also use technologies to fulfil the legal obligations to which we are subject (e.g. to be able to provide evidence of consent to the processing of your personal data), as well as for web analytics and online marketing. Further information on this, including the respective legal basis for data processing, can be found in the following sections of this privacy policy.
Cookie settings
The cookie settings for your browser can be found via the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™
Provided you have consented to the use of these technologies in accordance with Article 6(1)(a) of the GDPR, you may withdraw your consent at any time by contacting us via the contact details provided in the privacy policy. Alternatively, you can also visit the following link: https://www.travelite.com/de. If you do not accept cookies, the functionality of our website may be restricted.
6.2 Consent Manager Platform (CMP)
On our website, we use a consent management service (“Consent Manager Platform (CMP)”) to inform you about the cookies and other technologies we use on our website, and to obtain, manage and document your consent – where required – to the processing of your personal data by these technologies. This is necessary under Article 6(1), first sentence, point (c) of the GDPR to fulfil our legal obligation under Article 7(1) of the GDPR to be able to demonstrate your consent to the processing of your personal data, to which we are subject. The Consent Manager Platform (CMP) used is a service provided by ACRIS E-Commerce GmbH, Am Pfenningberg 60, 4040 Linz, Austria, which processes your data on our behalf.
Once you have submitted your cookie consent on our website, the web server stores the following data: IP address, device information, browser information, language setting, the webpage accessed or its URL, the date and time of your declaration of consent, and information regarding your consent behaviour.
In addition, the following technologies are used, which contain information about your consent behaviour: cookies
The data is stored exclusively on the end device; no personal data is transferred to the provider of the Consent Manager Platform (CMP). Your data will be deleted after 30 days, unless you have expressly consented to the further use of your data in accordance with Article 6(1)(a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this statement.
6.3 Information on transfers to third countries (data transfers to third countries)
We use technologies from service providers on our website whose registered offices and/or server locations may be situated in third countries, outside the EU or the EEA. If there is no adequacy decision by the European Commission for that country, an adequate level of data protection must be ensured by means of other suitable safeguards.
Appropriate safeguards in the form of contractually agreed standard contractual clauses issued by the European Commission or binding corporate rules (BCRs) are, in principle, possible; however, the contracting parties must first verify whether an adequate level of protection can be guaranteed. According to the case law of the Court of Justice of the European Union, it may be necessary to implement additional safeguards in this regard.
We have, as a matter of principle, agreed to the Standard Data Protection Clauses issued by the European Commission with the technology providers we use who process personal data in a third country. Where possible, we also agree on additional safeguards designed to ensure that an adequate level of data protection is guaranteed in third countries without an adequacy decision.
Notwithstanding this, it may be the case that, despite all contractual and technical measures, the level of data protection in the third country does not correspond to that of the EU. In such cases, we ask you, where necessary as part of the cookie consent process, to give your consent in accordance with Article 49(1)(a) of the GDPR to the transfer of your personal data to a third country.
In particular, there is a risk that local authorities in the third country may, from a European data protection perspective, be granted access rights to your personal data that are not sufficiently restricted, that we, as the data exporter, or you, as the data subject, may not be aware of this, and/or that you may not have sufficient legal remedies available to prevent this and/or to take action against such access.
In particular, the following countries are currently classified as third countries without an adequacy decision by the European Commission (examples include):
- China
- Russia
- Taiwan
You can find out to which third countries we transfer data in the privacy notices for the respective tool used and/or the consent management service we use (Consent Manager Platform, CMP).
7. Use of cookies and other technologies
We use the following cookies and other third-party technologies on our website. Unless otherwise stated for the individual technologies, this is done on the basis of your consent in accordance with Article 6(1), first sentence, point (a) of the GDPR. Once the purpose has ceased to apply and we have stopped using the relevant technology, the data collected in this context will be deleted. You may withdraw your consent at any time with future effect. Further information on your options for withdrawal can be found in the section "Cookies and other technologies". Further information, including the legal basis for our cooperation with the individual providers, can be found under the descriptions of the individual technologies. If you have any questions regarding the providers and the legal basis for our cooperation with them, please use the contact details provided in this privacy policy.
7.1 Use of Google services
We use the technologies of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”) described below. The information automatically collected by Google’s technologies regarding your use of our website is generally transmitted to and stored on a server operated by Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. Unless otherwise specified for the individual technologies, data processing is carried out on the basis of an agreement concluded between joint controllers for the respective technology in accordance with Article 26 of the GDPR. Further information on data processing by Google can be found in the Google privacy policy.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by means of a decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
Google Analytics
For the purposes of website analysis, data (IP address, time of visit, device and browser information, and information regarding your use of our website) is automatically collected and stored via Google Analytics; this data is used to create usage profiles using pseudonyms. Cookies may be used for this purpose. If you visit our website from within the EU, your IP address is stored on a server located in the EU for the purpose of deriving location data and is then immediately deleted before the traffic is forwarded to other Google servers for processing. Data processing is carried out on the basis of a data processing agreement with Google.
If you do not give us consent in accordance with Article 6(1)(a) of the GDPR for the use of Google Analytics, no cookies will be stored on or read from your device. The data processing described in the preceding paragraphs will not take place. To fill gaps in web analytics through behavioural and conversion modelling, pings containing data (user agent, information on your consent behaviour, screen resolution, IP address) are sent to Google.
Google Ads
For advertising purposes in Google search results and on third-party websites, when you visit our website, the so-called Google Remarketing cookie is set, which automatically enables interest-based advertising through the collection and processing of data (IP address, time of visit, device and browser information, and information regarding your use of our website), using a pseudonymous cookie ID and based on the pages you have visited. Any further data processing only takes place if you have enabled the ‘personalised advertising’ setting in your Google account. In this case, if you are logged into Google whilst visiting our website, Google will use your data in conjunction with Google Analytics data to create and define audience lists for cross-device remarketing.
For website analysis and event tracking, we use Google Ads Conversion Tracking to track your subsequent usage behaviour if you have arrived at our website via a Google Ads advertisement. To this end, cookies may be used and data (IP address, time of visit, device and browser information, as well as information regarding your use of our website based on events specified by us, such as visiting a webpage or subscribing to a newsletter) may be collected, from which usage profiles are created using pseudonyms.
If you do not give us consent in accordance with Article 6(1)(a) of the GDPR for the use of Google Ads, no cookies will be stored on or read from your device. The data processing described in the preceding paragraphs will not take place. To close gaps in web analytics through behavioural and conversion modelling, pings containing data (user agent, information on your consent behaviour, screen resolution, IP address, page URL, information on ad clicks in URL parameters) are sent to Google. Your IP address is used to determine the country of origin.
Google Maps
For the visual representation of geographical information, Google Maps collects data relating to your use of the Maps functions, in particular your IP address and location data, which is transmitted to Google and subsequently processed by Google. We have no influence over this subsequent data processing.
Google reCAPTCHA
To protect against misuse of our web forms and against spam generated by automated software (so-called bots), Google reCAPTCHA collects data (IP address, time of visit, browser information and information regarding your use of our website) and analyses your use of our website using JavaScript and cookies. In addition, other cookies stored in your browser by Google services are analysed. No personal data is read or stored from the input fields of the respective form.
Google Fonts
To ensure consistent presentation of content on our website, data (IP address, time of visit, device and browser information) is collected via the script code “Google Fonts”, transmitted to Google and subsequently processed by Google. We have no influence over this subsequent data processing.
Google Tag Manager
Google Tag Manager enables us to manage various codes and services on our website. When implementing the individual tags, Google may also process personal data (e.g. IP address, online identifiers (including cookies)). Data processing is carried out on the basis of a data processing agreement with Google.
The use of Google Tag Manager enables the integration of various services/technologies.
If you do not wish to use individual tracking services and have therefore disabled them, this deactivation will remain in place for all relevant tracking tags integrated via Google Tag Manager.
YouTube Video Plugin
When embedding third-party content via the YouTube video plugin in the enhanced privacy mode we use, data (IP address, time of visit, device and browser information) is collected, transmitted to Google and subsequently processed by Google only if you play a video.
7.2 Use of Facebook services
Use of Facebook Pixel
We use the Facebook Pixel as part of the technologies described below provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Facebook (by Meta)” or “Meta Platforms Ireland”). The Facebook Pixel automatically collects and stores data (IP address, time of visit, device and browser information, as well as information on your use of our website based on events specified by us, such as visiting a webpage or subscribing to a newsletter), from which usage profiles are created using pseudonyms.
As part of what is known as extended data matching, information that can be used to identify individuals (e.g. names, email addresses and telephone numbers) is also collected and stored in hashed form for matching purposes.
To this end, when you visit our website, the Facebook Pixel automatically sets a cookie which, by means of a pseudonymous cookie ID, enables your browser to be recognised when you visit other websites. Facebook (by Meta) will combine this information with other data from your Facebook account and use it to compile reports on website activity and to provide other services related to website usage, in particular personalised and group-based advertising.
The information automatically collected by Facebook (by Meta) technologies regarding your use of our website is generally transmitted to and stored on a server operated by Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Further information on data processing by Facebook can be found in the Facebook (by Meta) privacy policy.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined that an adequate level of data protection exists: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been obtained.
Our service providers are based in and/or use servers in the following countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the following safeguards: European Commission’s Standard Data Protection Clauses.
Facebook Analytics
As part of Facebook Business Tools, statistics on visitor activity on our website are generated from the data collected via the Facebook Pixel regarding your use of our website. Data processing is carried out on the basis of a data processing agreement with Facebook (by Meta). This analysis is used to optimise the presentation and marketing of our website.
Facebook Ads (Ads Manager)
We use Facebook Ads to advertise this website on Facebook (by Meta) and on other platforms. We determine the parameters of the respective advertising campaign. Facebook (by Meta) is responsible for the precise implementation, in particular for deciding where to place the adverts for individual users. Unless otherwise specified for the individual technologies, data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Joint controllership is limited to the collection of data and its transfer to Meta Platforms Ireland. Subsequent data processing by Meta Platforms Ireland is not covered by this.
Based on the statistics generated via Facebook Pixel regarding visitor activity on our website, we use Facebook Custom Audience to run group-based advertising on Facebook (by Meta), by defining the characteristics of the respective target audience. As part of the extended data matching process carried out to determine the respective target audience (see above), Facebook (by Meta) acts as our data processor.
Based on the pseudonymous cookie ID set by the Facebook Pixel and the data collected regarding your usage behaviour on our website, we use the Facebook Pixel to carry out remarketing personalised advertising.
Via Facebook Pixel Conversions we use to analyse your subsequent usage behaviour for web analytics and event tracking if you have reached our website via a Facebook Ads advertisement. Data processing is carried out on the basis of a data processing agreement with Facebook (by Meta).
7.3 Other providers of web analytics and online marketing services
Use of AdCell retargeting for online marketing
Use of AdCell retargeting for online marketing Through our advertising partner Firstlead GmbH, Rosenfelder Str. 15-16, 10315 Berlin (“adcell”), we advertise this website in search results and on third-party websites. When you visit our website, a retargeting cookie is automatically set by adcell or its partners; this enables interest-based advertising using a pseudonymous cookie ID and based on the pages you have visited. Data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. We determine the parameters of the respective advertising campaign. adcell is responsible for the precise implementation (e.g. deciding on the placement of individual adverts). The data automatically collected by adcell (IP address, time of visit, device and browser information, and information about your use of our website) may be combined by adcell with information from other sources and transmitted to adcell’s advertising partners.
Customa
This website uses technologies provided by customa to collect and store data for marketing and optimisation purposes. The provider of this technology is trust in dialog Services GmbH, Merkurring 33-35, 22143 Hamburg, https://www.customa.de. Cookies may be used for this purpose. Cookies are text files that are stored locally in the cache of the website visitor’s web browser. Cookies enable the web browser to be recognised.
Eye-Able Accessibility
Eye-Able® is software developed by Web Inclusion GmbH to ensure that everyone has barrier-free access to information on the internet. The necessary files, such as JavaScript, stylesheets and images, are loaded from an external server for this purpose. When functions are activated, Eye-Able® uses the browser’s local storage to save the settings. All settings are stored locally only and are not transmitted further. To ward off attacks and provide our service in near real time, Eye-Able® uses the Content Delivery Network (CDN) provided by BunnyWay d.o.o. (Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia). This is done for the purpose of fulfilling our contractual obligations to our customers (Article 6(1)(b) of the GDPR) and in the interests of ensuring the secure, fast and efficient provision of our online service by a professional provider (Article 6(1)(f) of the GDPR). All data transmitted and all servers remain within the EU at all times to ensure processing complies with the GDPR. Web Inclusion GmbH does not, at any time, collect or analyse personal user behaviour or other personal data. To ensure processing complies with data protection regulations, Web Inclusion GmbH has entered into data processing agreements with our hosting provider, BunnyWay. Further information can be found in the privacy policies: https://eye-able.com/datenschutz-eye-able/ https://bunny.net/privacy
Neo Commerce
I .We have integrated the Neocom guided-selling service provided by Neo Commerce GmbH (hereinafter “Neocom”), Max-Bill-Str. 8, 80807 Munich, onto our website to provide you with a digital, interactive product advisory service. When you start this product advice service, you can find your desired product through a quiz-style, guided process and, at the end, receive a product recommendation which you can then have sent to you by email if you wish.
II. During the consultation, Neocom collects the following browser HTTP information: browser type and version, IP address, and browser language. In addition, a session ID is generated and temporarily stored on your device during the browser session in order to provide the advice. The purpose is to enable the correct and complete display and execution of the digital product advice, similar to a shopping basket function. The legal basis is our legitimate interest pursuant to Article 6(1), first sentence, point (f) of the GDPR (browser query) and Article 6(1), first sentence, point (a) of the GDPR (consent regarding the session ID).
III. Furthermore, a persistent Neocom session ID is stored. This is a purchase tracking tool used to determine whether a purchase has been made with us following the product consultation – even across multiple browser sessions. However, this only takes place with your prior consent. The legal basis is therefore Article 6(1), first sentence, point (a) of the GDPR. The session ID is deleted after 365 days at the latest.
IV. Your email address is requested in order to send you product recommendations by email, if you so wish. Neocom uses this address solely for the purpose of sending you the information you have requested. However, this is only done with your prior consent. The legal basis for this is therefore Article 6(1), first sentence, point (a) of the GDPR. We use the so-called “double opt-in procedure”. Once you have provided your email address, we will send you an email containing a confirmation link to confirm your request to receive the product recommendation. If you click on this confirmation link, your email address will be stored for the purpose of sending the email. If you do not click on the confirmation link within 24 hours, your registration details will be blocked. You may withdraw your consent to the processing of personal data pursuant to Article 6(1), first sentence, point (a) of the GDPR at any time. If you contact us by email, you may object to the storage of your personal data at any time.
V. Neocom uses additional services for product advice. Details of these can be found here.
VI. Use of Neocom product advice within AI-based assistance systems.
Additionally, it is possible to use the Neocom product advice service via AI-supported assistance systems. In some cases, interaction takes place via free-text inputs from users. Personal information may also be transmitted in this context. Please note that the use of free-text input is voluntary and no sensitive information is required. Where technically necessary, this input is processed and stored in accordance with recognised best-practice standards, where appropriate in anonymised or pseudonymised form. The data is encrypted at the access level using state-of-the-art technology (AES-256). Processing is carried out solely for the purpose of providing and optimising the interactive product advice service. In individual cases, this may involve the transfer of data to service providers in third countries outside the EU. In such cases, we ensure that appropriate safeguards are in place in accordance with Article 44 ff. of the GDPR. Use of the AI-based version is optional; alternatively, a fully click-based experience remains available. The legal basis is your consent in accordance with Article 6(1), first sentence, point (a) of the GDPR.
Use of Hotjar
For the purpose of website analysis, technologies provided by Hotjar Ltd., Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 3155, Malta (“Hotjar”) automatically collect and store data (IP address, time of visit, device and browser information, and information regarding your use of our website), from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. The pseudonymised usage profiles will not be merged with personal data relating to the holder of the pseudonym without separate, explicit consent. Hotjar acts on our behalf.
Use of Vimeo Video Plugin for embedding third-party content
To embed third-party content, data (IP address, time of visit, device and browser information) is collected via the video plugin of Vimeo Inc., 330 West 34th Street, 5th Floor, New York 10011, USA (“Vimeo”), transmitted to Vimeo and subsequently processed by Vimeo. Data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Google Analytics is automatically integrated into the Vimeo video plugin. For the purpose of website analysis, Google Analytics automatically collects and stores data (IP address, time of visit, device and browser information, and information regarding your use of our website), from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. Google Analytics is a service provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by Google regarding your use of our website is generally transferred to a server operated by Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA, and stored there. If you visit our website from within the EU, your IP address is stored on a server located in the EU for the purpose of deriving location data and is then immediately deleted before the traffic is forwarded to other Google servers for processing. We have no influence over or access to the data processing carried out by Vimeo, including the settings and results of Google Analytics.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by means of a decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
8. Integration of the Trusted Shops Trustbadge/ other widgets
Provided you have given your consent in accordance with Article 6(1), first sentence, point (a) of the GDPR, Trusted Shops widgets are integrated into this website to display Trusted Shops services (e.g. quality seals, collected reviews) and to offer Trusted Shops products to buyers following an order.
The Trustbadge and the services advertised via it are provided by Trusted Shops SE, Subbelrather Str. 15C, 50823 Cologne ("Trusted Shops"), with whom we are joint data controllers under Article 26 of the GDPR. In this privacy notice, we set out below the key terms of the agreement in accordance with Article 26(2) of the GDPR.
As part of the joint responsibility between us and Trusted Shops SE, please contact Trusted Shops in the first instance regarding data protection queries and to exercise your rights, using the contact details provided in the privacy policy. Regardless of this, you may always contact the data controller of your choice. Your enquiry will then, if necessary, be forwarded to the other data controller for a response.
8.1 Data processing when integrating the Trustbadge/ other widgets
The Trustbadge is provided by a US-based CDN provider (Content-Delivery-Network). An adequate level of data protection is ensured in each case by an adequacy decision of the EU Commission, which can be accessed here for the USA. Service providers based in the USA are generally certified under the EU-U.S. Data Privacy Framework (DPF). Further information is available here. Where service providers are not certified under the DPF, standard contractual clauses have been agreed as an appropriate safeguard.
When the Trustbadge is accessed, the web server automatically stores a so-called server log file, which also contains your IP address, the date and time of access, the amount of data transferred and the requesting provider (access data), and documents the access. The IP address is anonymised immediately after collection, so that the stored data cannot be linked to you personally. The anonymised data is used in particular for statistical purposes and for error analysis.
8.2 Data processing after completion of an order
Provided you have given your consent, once the order has been completed, the Trustbadge will access the order information stored on your device (order total, order number, and, where applicable, the product purchased), and your email address is hashed using a cryptographic one-way function. The hash value is then transmitted to Trusted Shops together with the order information in accordance with Article 6(1), first sentence, point (a) of the GDPR.
This is to check whether you are already registered for Trusted Shops’ services. If this is the case, further processing will take place in accordance with the contractual agreement between you and Trusted Shops. If you are not yet registered for the services or do not give your consent to automatic recognition via the Trustbadge, you will then be given the option to register manually to use the services or to finalise the terms of your existing user agreement, if applicable.
For this purpose, once you have completed your order, the Trustbadge accesses the following information stored on the device you are using: order total, order number and email address. This is necessary so that we can offer you buyer protection. The data will only be transmitted to Trusted Shops once you have actively opted to take out buyer protection by clicking on the button labelled as such in the so-called Trustcard. If you decide to use the services, further processing is governed by the contractual agreement with Trusted Shops in accordance with Article 6(1)(b) of the GDPR, in order to complete your registration for buyer protection, secure your order and, where applicable, subsequently send you review invitations by email.
Trusted Shops uses service providers in the areas of hosting, monitoring and logging. The legal basis for this is Article 6(1)(f) of the GDPR, for the purpose of ensuring trouble-free operation. In doing so, processing may take place in third countries (USA, Great Britain and Israel). An adequate level of data protection is ensured in each case by an adequacy decision of the EU Commission, which can be accessed here for the USA, here for Great Britain and here for Israel. Service providers based in the USA are generally certified under the EU-U.S. Data Privacy Framework (DPF). Further information is available here. Where service providers are not certified under the DPF, standard contractual clauses have been agreed as an appropriate safeguard.
9. Social media
9.1 Social buttons from Facebook (by Meta), Instagram (by Meta)
Our website uses social media buttons from social networks. These are simply embedded in the page as HTML links, meaning that no connection to the respective provider’s servers is established when you visit our website. If you click on one of the buttons, the website of the relevant social network will open in a new browser window There, you can, for example, click the ‘Like’ or ‘Share’ button.
9.2 Our online presence on Facebook (by Meta), Instagram (by Meta), YouTube, Pinterest, LinkedIn, Xing
Provided that you have given your consent to the relevant social media operator in accordance with Article 6(1), first sentence, point (a) of the GDPR, when you visit our online presence on the social media platforms mentioned above, your data will be automatically collected and stored for market research and advertising purposes, from which usage profiles are created using pseudonyms. These may be used, for example, to display advertisements both within and outside the platforms that are presumed to match your interests. Cookies are generally used for this purpose. For detailed information on the processing and use of data by the relevant social media operator, as well as contact details, your rights in this regard and settings to protect your privacy, please refer to the providers’ privacy policies linked below. Should you nevertheless require assistance in this matter, please do not hesitate to contact us.
Facebook (by Meta) is a service provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Meta Platforms Ireland”). The information automatically collected by Meta Platforms Ireland regarding your use of our online presence on Facebook (by Meta) is generally transferred to and stored on a server belonging to Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Data processing in connection with a visit to a Facebook (by Meta) fan page is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Further information (information on Insights data) can be found here.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined that an adequate level of data protection exists: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been obtained.
Our service providers are based in and/or use servers in the following countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico.
There is no adequacy decision from the European Commission for these countries. Our cooperation with them is based on these safeguards: European Commission’s Standard Data Protection Clauses.
Instagram (by Meta) is a service provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Meta Platforms Ireland”). The information automatically collected by Meta Platforms Ireland regarding your use of our online presence on Instagram is generally transmitted to a server operated by Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA, Menlo Park, California 94025, USA and stored there. Data processing in connection with a visit to an Instagram (by Meta) fan page is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Further information (information on Insights data) can be found here.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined that an adequate level of data protection exists: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been obtained.
Our service providers are based in and/or use servers in the following countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico.
There is no adequacy decision by the European Commission for these countries. Our cooperation with you is based on these safeguards: European Commission’s Standard Data Protection Clauses.
YouTube is a service provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by Google regarding your use of our online presence on YouTube is generally transmitted to and stored on a server operated by Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by means of a decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
Pinterest is a service provided by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland (“Pinterest”). The information automatically collected by Pinterest regarding your use of our online presence on Pinterest is generally transmitted to and stored on a server operated by Pinterest, Inc., 505 Brannan St., San Francisco, CA 94107, USA.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by means of a decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
LinkedIn is a service provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”). The information automatically collected by LinkedIn regarding your use of our online presence on LinkedIn is generally transmitted to and stored on a server belonging to LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined that an adequate level of data protection exists: USA.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been obtained.
Xing is a service provided by New Work SE, Am Strandkai 1, 20457 Hamburg, Germany.
10. Contact details and your rights
10.1 Your rights
As a data subject, you have the following rights:
- in accordance with Article 15 of the GDPR, the right to request information, to the extent specified therein, regarding your personal data processed by us;
- in accordance with Article 16 of the GDPR, the right to request, without delay, the rectification of inaccurate personal data or the completion of your personal data stored by us;
- in accordance with Article 17 of the GDPR, you have the right to request the erasure of your personal data stored by us, unless further processing
- to exercise the right to freedom of expression and information;
- to fulfil a legal obligation;
- for reasons of public interest or
- is necessary for the assertion, exercise or defence of legal claims;
- in accordance with Article 18 of the GDPR, the right to request the restriction of the processing of your personal data, insofar as
- you dispute the accuracy of the data;
- the processing is unlawful, but you object to its erasure;
- we no longer require the data, but you require it to assert, exercise or defend legal claims, or
- you have objected to the processing in accordance with Article 21 of the GDPR;
- in accordance with Article 20 of the GDPR, the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transferred to another controller;
- in accordance with Article 77 of the GDPR, the right to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority for your usual place of residence or workplace, or for the location of our company’s registered office.
| Right to object Where we process personal data as explained above to safeguard our legitimate interests, which prevail following a balancing of interests, you may object to this processing with effect for the future. If the processing is carried out for direct marketing purposes, you may exercise this right at any time as described above. Where the processing is carried out for other purposes, you have a right to object only if there are grounds arising from your particular situation. Once you have exercised your right to object, we will no longer process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or where the processing serves to establish, exercise or defend legal claims. This does not apply if the processing is carried out for direct marketing purposes. In that case, we will not process your personal data further for this purpose. |
10.2 Contact details
If you have any questions regarding the collection, processing or use of your personal data, or if you wish to request information, rectification, restriction or erasure of data, or to withdraw consent previously given or object to a specific use of your data, please contact us directly using the contact details provided in our legal notice.
Data Protection Officer:
SHIELD GmbH Martin Vogel
Ohlrattweg 5
25497 Prisdorf
Germany
info@shield-datenschutz.de
Privacy Policy
hosting
2. Data processing for contract fulfilment and for establishing contact
2.1 Data processing for the fulfilment of the contract
2.2 Customer account
2.3 Microsoft 365, including Outlook and Microsoft 365 Copilot
2.4 Contacting us
3. Data processing for the purpose of order fulfilment
Data transfer to delivery service providers for the purpose of dispatch notification
4. Data processing for payment processing
4.1 Data processing for transaction processing
4.2 Data processing for the purposes of fraud prevention and optimising our payment processes
4.3 Identity and credit checks when selecting Klarna payment services
5. Advertising by email
5.1 Email newsletter with subscription, newsletter tracking with separate consent
5.2 Newsletter distribution
5.3 Sending requests for reviews by email
6. Cookies and other technologies
6.1 General information
6.2 Consent Manager Platform (CMP)
6.3 Information on transfers to third countries (data transfers to third countries)
7. Use of cookies and other technologies
7.1 Use of Google services
7.2 Use of Facebook services
7.3 Other providers of web analytics and online marketing services
8. Integration of the Trusted Shops Trustbadge and other widgets
8.1 Data processing when integrating the Trustbadge or other widgets
8.2 Data processing following completion of an order
9. Social media
9.1 Social buttons from Facebook (by Meta) and Instagram (by Meta)
9.2 Our online presence on Facebook (by Meta), Instagram (by Meta), YouTube, Pinterest, LinkedIn and Xing
10. Contact details and your rights
10.1 Your rights
10.2 Contact details
The data controller is:
travelite GmbH + Co. KG
Merkurring 70-72
22143 Hamburg
Email: info@travelite.de
We appreciate your interest in our online shop. Protecting your privacy is very important to us. Below, we provide detailed information on how we handle your data.
1. Access data and hosting
You can visit our websites without providing any personal information. Each time you access a webpage, the web server automatically stores a so-called server log file, which contains, for example, the name of the requested file, your IP address, the date and time of the request, the amount of data transferred and the requesting provider (access data), and documents the request. This access data is analysed solely for the purpose of ensuring the smooth operation of the website and improving our service. This serves to safeguard our legitimate interests, which prevail following a balancing of interests, in the correct presentation of our services in accordance with Article 6(1)(f) of the GDPR. All access data is deleted no later than seven days after the end of your visit to the site.
Hosting
The services for hosting and displaying the website are partly provided by our service providers as part of data processing on our behalf. Unless otherwise stated in this privacy policy, all access data and all data collected via the forms provided for this purpose on this website are processed on their servers. If you have any questions regarding our service providers and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined that an adequate level of data protection exists: the United Kingdom, Canada and the USA.
A decision by the European Commission on an adequate level of data protection for the USA serves as the basis for data transfers to third countries, provided that the relevant service provider is certified. Pending certification by our service providers, data transfers will continue to be based on the following: the European Commission’s Standard Data Protection Clauses
Our service providers are based in and/or use servers in the following countries: Australia.
There is no adequacy decision by the European Commission for these countries. Our cooperation with you is based on these safeguards: the European Commission’s Standard Data Protection Clauses.
2. Data processing for contract fulfilment and for establishing contact
2.1 Data processing for the fulfilment of the contract
For the purpose of contract fulfilment (including enquiries regarding and the handling of any existing warranty claims and claims for breach of contract, as well as any statutory obligations to provide updates) in accordance with Article 6(1), first sentence, point (b) of the GDPR, we collect personal data if you voluntarily provide it to us as part of your order. Mandatory fields are marked as such, as in these cases we require the data to fulfil the contract and cannot dispatch the order without it. The data collected is specified in the relevant input forms.
Further information on the processing of your data, in particular regarding its transfer to our service providers for the purposes of order, payment and dispatch processing, can be found in the following sections of this privacy policy. Once the contract has been fully fulfilled, your data will be restricted for further processing and deleted upon expiry of the retention periods under tax and commercial law in accordance with Article 6(1), first sentence, point (c) of the GDPR, unless you have expressly consented to the further use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy.
Merchandise management system
We use external service providers’ merchandise management systems for order and contract processing. Our service providers act on our behalf within the framework of data processing on our behalf. If you have any questions regarding our service providers or the basis of our cooperation with them, please use the contact details provided in this privacy policy.
2.2 Customer account
Provided that you have given your consent to this in accordance with Article 6(1)(a) of the GDPR by choosing to open a customer account, we will use your data for the purpose of opening your customer account and for storing your data for future orders on our website. You may delete your customer account at any time, either by contacting us via the contact details provided in this privacy policy or by using the function provided for this purpose within your customer account. Once your customer account has been deleted, your data will be deleted, unless you have expressly consented to the further use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy.
2.3 Microsoft 365, including Outlook and Microsoft 365 Copilot
We use “Microsoft 365” including Outlook and Microsoft 365 Copilot. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (hereinafter referred to as “Microsoft”).
Microsoft 365 is a platform for communication, collaboration, appointment management, file storage, document editing and the organisation of business processes. When using Microsoft 365, the following data in particular may be processed: master data, contact details, communication data, content data, email data, file and document content, appointment and calendar data, contract data, usage data, technical data and metadata. When using Outlook, the following data in particular may be processed: names, email addresses, email content, email attachments, subject lines, send and receive times, and other communication metadata.
We also use Microsoft 365 Copilot to support our work with Microsoft 365. Depending on usage, configuration and the permissions model, Microsoft 365 Copilot may process content from Microsoft 365. This may include, in particular, emails, calendar information, contacts, files, document content, meeting content, chat and communication data, as well as other information from Microsoft 365. This processing is carried out, in particular, to search for information, summarise content, create and revise texts, prepare work processes and support internal organisation. Microsoft 365 Copilot processes content within the framework of the configured authorization policy and, in principle, can only take into account content to which the respective user is authorized to access.
The processing of personal data may also take place in third countries, in particular in the USA. This may be the case, in particular, in relation to support services, security and error analyses, telemetry, the use of sub-processors or, depending on the configuration of individual Microsoft services. With Microsoft 365 Copilot, depending on settings and the availability of features, individual processing operations – in particular processing by large language models – may also take place outside the EU Data Boundary. In this regard, Microsoft describes the option of so-called ‘Flex Routing’ for EU and EFTA customers, whereby LLM inference may take place outside the EU Data Boundary under certain conditions.
Where personal data is transferred to Microsoft in the USA or processed there, Microsoft bases the data transfer to the USA on the European Commission’s EU-US Data Privacy Framework. Where Microsoft transfers personal data to other third countries or has it processed by sub-processors in other third countries, Microsoft states that it bases these transfers additionally on appropriate safeguards, in particular standard contractual clauses within the meaning of Article 46 of the GDPR.
Where processing is necessary for the implementation of pre-contractual measures or a contract with you, it is carried out on the basis of Article 6(1)(b) of the GDPR. Where processing is carried out to safeguard our legitimate interests, it is carried out on the basis of Article 6(1)(f) of the GDPR. Our legitimate interests lie in efficient communication, the secure organisation of our business processes, structured collaboration, the documentation of business transactions, the handling of enquiries, and supporting our employees in carrying out their business tasks. Where we are legally obliged to retain certain communications, documents or business transactions, processing is carried out on the basis of Article 6(1)(c) of the GDPR. Where special categories of personal data are processed in individual cases, this is done only where there is a legal basis for doing so under Article 9 of the GDPR.
Microsoft processes personal data insofar as such processing is carried out on our behalf for the provision and operation of Microsoft 365 including Outlook and Microsoft 365 Copilot, as a data processor within the meaning of Article 4(8) of the GDPR. We have concluded a data processing agreement with Microsoft within the meaning of Article 28(3) of the GDPR. In this agreement, Microsoft undertakes, in particular, to process personal data only in accordance with our instructions and for the purpose of providing the agreed services, to implement appropriate technical and organisational safeguards, and to engage sub-processors only in accordance with the contractual provisions.
Further information on data processing by Microsoft can be found at https://www.microsoft.com/de-de/privacy/privacystatement . Further information on the Microsoft Products and Services Data Protection Addendum can be found at https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA
2.4 Contacting us
As part of our customer communications, we collect personal data to process your enquiries in accordance with Article 6(1)(b) of the GDPR if you voluntarily provide this to us when contacting us (e.g. via the contact form, live chat tool or email). Mandatory fields are marked as such, as we require this data in these cases to process your enquiry. The data collected is specified in the respective input forms. Once your enquiry has been fully processed, your data will be deleted, unless you have expressly consented to further use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy.
3. Data processing for the purpose of order fulfilment
To fulfil the contract in accordance with Article 6(1)(b) of the GDPR, we pass on your data to the delivery service provider commissioned to carry out the delivery, insofar as this is necessary for the delivery of the goods ordered. If you have any questions regarding our service providers and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
Data transfer to delivery service providers for the purpose of dispatch notification
Provided you have given us your explicit consent to this during or after placing your order, we will, on this basis and in accordance with Article 6(1)(a) of the GDPR, pass on your email address to the selected delivery service provider, so that they can contact you prior to delivery to notify you of the delivery or to coordinate it.
Consent may be withdrawn at any time by sending a message via the contact details provided in this privacy policy or directly to the delivery service provider at the contact address listed below. Following revocation, we will delete the data you have provided for this purpose, unless you have expressly consented to the continued use of your data or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this policy. If you have any questions regarding our service providers and the basis of our cooperation with them, please contact us using the contact details provided in this privacy policy.
DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Germany
DPD Deutschland GmbH
Wailandtstraße 1
63741 Aschaffenburg
Germany
4. Data processing for payment processing
When processing payments in our online shop, we work with the following partners: technical service providers, credit institutions, payment service providers.
4.1 Data processing for transaction processing
Depending on the selected payment method, we pass on the data necessary for processing the payment transaction to our technical service providers, who act on our behalf as data processors, or to the commissioned credit institutions or the selected payment service provider, insofar as this is necessary to process the payment. This serves the purpose of fulfilling the contract in accordance with Article 6(1), first sentence, point (b) of the GDPR. In some cases, the payment service providers collect the data required to process the payment themselves, e.g. on their own website or via a technical integration into the ordering process. In this respect, the privacy policy of the respective payment service provider applies.
If you have any questions regarding our payment processing partners and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
4.2 Data processing for the purposes of fraud prevention and optimising our payment processes
Where necessary, we may provide our service providers with further data, which they use together with the data required to process the payment in their capacity as our data processors for the purposes of fraud prevention and optimising our payment processes (e.g. invoicing, handling disputed payments, supporting our accounts department). This serves, in accordance with Article 6(1), first sentence, point (f) of the GDPR, to safeguard our legitimate interests which, following a balancing of interests, are deemed to prevail in protecting ourselves against fraud and in ensuring efficient payment management.
4.3 Identity and credit checks when selecting Klarna payment services
Purchase on account via Klarna
If you opt to use the payment services provided by Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter ‘Klarna’), we ask for your consent in accordance with Article 6(1)(a) of the GDPR to allow us to transfer to Klarna the data necessary for processing the payment and carrying out an identity and creditworthiness check. In Germany, the credit reference agencies listed in Klarna’s privacy policy may be used for identity and credit checks. Klarna uses the information received regarding the statistical probability of payment default to make a balanced decision on whether to enter into, continue or terminate the contractual relationship. You may withdraw your consent at any time by contacting us via the contact details provided in this privacy policy. This may mean that we are no longer able to offer you certain payment options. You may also withdraw your consent to this use of personal data at any time by contacting Klarna directly.
5. Advertising by email
5.1 Email newsletter with subscription, newsletter tracking with separate consent
If you subscribe to our newsletter, we will use the data required for this purpose or data provided separately by you to send you our email newsletter on a regular basis, based on your consent in accordance with Article 6(1), first sentence, point (a) of the GDPR. You may unsubscribe from the newsletter at any time, either by contacting us via the details provided below or by clicking the link provided for this purpose in the newsletter. Once you have unsubscribed, we will remove your email address from the mailing list, unless you have expressly consented to the further use of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this statement.
If you have also given us your consent in accordance with Article 6(1)(a) of the GDPR to analyse our newsletters, we will also analyse your interaction with our newsletter by measuring, storing and evaluating open rates and click-through rates for the purpose of designing future newsletter campaigns (“newsletter tracking”).
For the purposes of this analysis, the emails sent contain single-pixel technologies (e.g. so-called web beacons, tracking pixels) that are stored on our website. For the analyses, we link the following “newsletter data”
- the page from which the page was requested (known as the referrer URL),
- the date and time of the visit,
- a description of the type of web browser used,
- the IP address of the requesting computer,
- the email address,
- the date and time of registration and confirmation
and the single-pixel technologies with your email address or your IP address and, where applicable, an individual ID. Links contained in the newsletter may also contain this ID.
You can unsubscribe from newsletter tracking at any time, either by sending a message via the contact details provided or by clicking on the link provided for this purpose in the newsletter.
The information will be stored for as long as you remain subscribed to the newsletter.
5.2 Newsletter distribution
The newsletter and the newsletter tracking described above may also be sent by our service providers as part of processing carried out on our behalf. If you have any questions regarding our service providers and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
5.3 Sending requests for reviews by email
Provided that you have given us your explicit consent in accordance with Article 6(1)(a) of the GDPR during or after placing your order, we will use your email address to request that you submit a review of your order via the review system we use. This consent may be withdrawn at any time by sending a message via the contact details provided in this privacy policy or via a link provided for this purpose in the review request. Once you have withdrawn your consent, we will delete your email address from the recipient list, provided that you have not expressly consented to the further processing of your data in accordance with Article 6(1), first sentence, point (a) of the GDPR, or we reserve the right to process your data for other purposes which are permitted by law and about which we inform you in this policy.
Where applicable, requests for reviews may also be sent by our service provider, Trusted Shops SE, Subbelrather Str. 15C, 50823 Cologne ("Trusted Shops").
In the course of sending review requests, we receive information from Trusted Shops regarding the respective status (e.g. whether the review request has been sent and whether it has been received). This is carried out in accordance with Article 6(1)(f) of the GDPR to fulfil our legitimate interest in receiving information about the review invitations, so that we can, where necessary, as well as to fulfil Trusted Shops’ legitimate interest in being able to offer this service.
We are jointly responsible with Trusted Shops for sending requests for reviews and for collecting and displaying review and status information.
As part of the joint responsibility between us and Trusted Shops, please contact Trusted Shops in the first instance regarding data protection queries and to exercise your rights; you can find their contact details here. Further information on data protection can be found via the following link here. Irrespective of this, you may also contact us at any time using the contact details provided in this privacy policy. Your enquiry will then, if necessary, be forwarded to the other data controller for a response.
6. Cookies and other technologies
6.1 General information
To make your visit to our website more engaging and to enable the use of certain functions, we use various technologies on different pages, including so-called cookies. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted at the end of the browser session, i.e. once you close your browser (so-called session cookies). Other cookies remain on your device and enable us to recognise your browser the next time you visit (persistent cookies). You can find the storage duration in the overview within your web browser’s cookie settings.
Privacy protection on end devices
When you use our online service, we employ technologies that are strictly necessary in order to provide the explicitly requested telemedia service. The storage of information on your device or access to information already stored on your device does not require your consent in this respect.
For functions that are not strictly necessary, the storage of information on your device or access to information already stored on your device requires your consent. Please note that if you do not give your consent, parts of the website may not be fully accessible. Any consent you have given will remain valid until you adjust or reset the relevant settings on your device.
Any subsequent data processing via cookies and other technologies
We use technologies that are strictly necessary for the use of certain functions on our website (e.g. the shopping basket function). These technologies collect and process your IP address, the time of your visit, device and browser information, as well as information regarding your use of our website (e.g. information about the contents of your shopping basket). This is based on a balancing of interests, where our overriding legitimate interests in optimising the presentation of our website prevail, in accordance with Article 6(1), first sentence, point (f) of the GDPR.
We also use technologies to fulfil the legal obligations to which we are subject (e.g. to be able to provide evidence of consent to the processing of your personal data), as well as for web analytics and online marketing. Further information on this, including the respective legal basis for data processing, can be found in the following sections of this privacy policy.
Cookie settings
The cookie settings for your browser can be found via the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™
Provided you have consented to the use of these technologies in accordance with Article 6(1)(a) of the GDPR, you may withdraw your consent at any time by contacting us via the contact details provided in the privacy policy. Alternatively, you can also visit the following link: https://www.travelite.com/de. If you do not accept cookies, the functionality of our website may be restricted.
6.2 Consent Manager Platform (CMP)
On our website, we use a consent management service (“Consent Manager Platform (CMP)”) to inform you about the cookies and other technologies we use on our website, and to obtain, manage and document your consent where required to the processing of your personal data by these technologies. This is necessary under Article 6(1), first sentence, point (c) of the GDPR to fulfil our legal obligation under Article 7(1) of the GDPR to be able to demonstrate your consent to the processing of your personal data, to which we are subject. The Consent Manager Platform (CMP) used is a service provided by ACRIS E-Commerce GmbH, Am Pfenningberg 60, 4040 Linz, Austria, which processes your data on our behalf.
Once you have submitted your cookie consent on our website, the web server stores the following data: IP address, device information, browser information, language setting, the webpage accessed or its URL, the date and time of your declaration of consent, and information regarding your consent behaviour.
In addition, the following technologies are used, which contain information about your consent behaviour: Cookies
The data is stored exclusively on the end device; no personal data is transferred to the provider of the Consent Manager Platform (CMP). Your data will be deleted after 30 days, unless you have expressly consented to the further use of your data in accordance with Article 6(1)(a) of the GDPR, or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this statement.
6.3 Information on transfers to third countries (data transfers to third countries)
We use technologies from service providers on our website whose registered offices and/or server locations may be situated in third countries, outside the EU or the EEA. If there is no adequacy decision by the European Commission for that country, an adequate level of data protection must be ensured by means of other suitable safeguards.
Appropriate safeguards in the form of contractually agreed standard contractual clauses issued by the European Commission or binding corporate rules (BCRs) are, in principle, possible; however, the contracting parties must first verify whether an adequate level of protection can be guaranteed. According to the case law of the Court of Justice of the European Union, it may be necessary to implement additional safeguards in this regard.
We have, as a matter of principle, agreed to the Standard Data Protection Clauses issued by the European Commission with the technology providers we use who process personal data in a third country. Where possible, we also agree on additional safeguards designed to ensure that an adequate level of data protection is guaranteed in third countries without an adequacy decision.
Notwithstanding this, it may be the case that, despite all contractual and technical measures, the level of data protection in the third country does not correspond to that of the EU. In such cases, we ask you, where necessary, as part of the cookie consent process, to give your consent in accordance with Article 49(1)(a) of the GDPR to the transfer of your personal data to a third country.
In particular, there is a risk that local authorities in the third country may, from a European data protection perspective, be granted access rights to your personal data that are not sufficiently restricted, that we, as the data exporter, or you, as the data subject, may not be aware of this, and/or that you may not have sufficient legal remedies available to prevent this and/or to take action against such access.
In particular, the following countries are currently classified as third countries without an adequacy decision by the European Commission (examples include):
- China
- Russia
- Taiwan
You can find out to which third countries we transfer data in the privacy notices for the respective tool used and/or the consent management service we use (Consent Manager Platform, CMP).
7. Use of cookies and other technologies
We use the following cookies and other third-party technologies on our website. Unless otherwise specified for the individual technologies, this is done on the basis of your consent in accordance with Article 6(1), first sentence, point (a) of the GDPR. Once the purpose has ceased to apply and we have stopped using the relevant technology, the data collected in this context will be deleted. You may withdraw your consent at any time with future effect. Further information on your options for withdrawal can be found in the section "Cookies and other technologies". Further information, including the legal basis for our cooperation with the individual providers, can be found under the descriptions of the individual technologies. If you have any questions regarding the providers and the legal basis for our cooperation with them, please use the contact details provided in this privacy policy.
7.1 Use of Google services
We use the technologies of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”) described below. The information automatically collected by Google’s technologies regarding your use of our website is generally transmitted to and stored on a server operated by Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. Unless otherwise specified for the individual technologies, data processing is carried out on the basis of an agreement concluded between joint controllers for the respective technology in accordance with Article 26 of the GDPR. Further information on data processing by Google can be found in the Google’s privacy policy.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by means of a decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
Google Analytics
For the purpose of website analysis, data (IP address, time of visit, device and browser information, and information regarding your use of our website) is automatically collected and stored via Google Analytics; this data is used to create usage profiles using pseudonyms. Cookies may be used for this purpose. If you visit our website from within the EU, your IP address is stored on a server located in the EU for the purpose of deriving location data and is then immediately deleted before the traffic is forwarded to other Google servers for processing. Data processing is carried out on the basis of a data processing agreement with Google.
If you do not give us consent in accordance with Article 6(1)(a) of the GDPR for the use of Google Analytics, no cookies will be stored on or read from your device. The data processing described in the preceding paragraphs will not take place. To fill gaps in web analytics through behavioural and conversion modelling, pings containing data (user agent, information on your consent behaviour, screen resolution, IP address) are sent to Google.
Google Ads
For advertising purposes in Google search results and on third-party websites, so-called Google Remarketing cookie is set; this automatically enables interest-based advertising through the collection and processing of data (IP address, time of visit, device and browser information, and information about your use of our website), using a pseudonymous cookie ID and based on the pages you have visited. Any further data processing only takes place if you have enabled the ‘personalised advertising’ setting in your Google account. In this case, if you are logged into Google whilst visiting our website, Google will use your data in conjunction with Google Analytics data to create and define audience lists for cross-device remarketing.
For website analysis and event tracking, we use Google Ads Conversion Tracking to measure your subsequent usage behaviour if you have arrived at our website via a Google Ads advertisement. To this end, cookies may be used and data (IP address, time of visit, device and browser information, as well as information regarding your use of our website based on events specified by us, such as visiting a web page or subscribing to a newsletter) may be collected, from which usage profiles are created using pseudonyms.
If you do not give us consent in accordance with Article 6(1)(a) of the GDPR for the use of Google Ads, no cookies will be stored on or read from your device. The data processing described in the preceding paragraphs will not take place. To close gaps in web analytics through behavioural and conversion modelling, pings containing data (user agent, information on your consent behaviour, screen resolution, IP address, page URL, information on ad clicks in URL parameters) are sent to Google. Your IP address is used to determine the country of origin.
Google Maps
For the visual representation of geographical information, Google Maps collects data relating to your use of the Maps functions, in particular your IP address and location data, which is transmitted to Google and subsequently processed by Google. We have no influence over this subsequent data processing.
Google reCAPTCHA
To protect against misuse of our web forms and against spam generated by automated software (so-called ‘bots’), Google reCAPTCHA collects data (IP address, time of visit, browser information and information regarding your use of our website) and analyses your use of our website using JavaScript and cookies. In addition, other cookies stored in your browser by Google services are analysed. No personal data is read or stored from the input fields of the respective form.
Google Fonts
To ensure consistent presentation of content on our website, data (IP address, time of visit, device and browser information) is collected via the ‘Google Fonts’ script code, transmitted to Google and subsequently processed by Google. We have no influence over this subsequent data processing.
Google Tag Manager
Google Tag Manager enables us to manage various codes and services on our website. When implementing the individual tags, Google may also process personal data (e.g. IP address, online identifiers (including cookies)). Data processing is carried out on the basis of a data processing agreement with Google.
The use of Google Tag Manager enables the integration of various services/technologies.
If you do not wish to use individual tracking services and have therefore disabled them, this deactivation will remain in effect for all relevant tracking tags integrated via Google Tag Manager.
YouTube Video Plugin
When embedding third-party content via the YouTube Video Plugin in the enhanced privacy mode we use, data (IP address, time of visit, device and browser information) is collected, transmitted to Google and subsequently processed by Google only if you play a video.
7.2 Use of Facebook services
Use of Facebook Pixel
We use the Facebook Pixel as part of the technologies described below provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Facebook (by Meta)” or “Meta Platforms Ireland”). The Facebook Pixel automatically collects and stores data (IP address, time of visit, device and browser information, as well as information on your use of our website based on events specified by us, such as visiting a webpage or subscribing to a newsletter), from which usage profiles are created using pseudonyms.
As part of what is known as ‘extended data matching’, information that can be used to identify individuals (e.g. names, email addresses and telephone numbers) is also collected and stored in hashed form for matching purposes.
To this end, when you visit our website, the Facebook Pixel automatically sets a cookie which, by means of a pseudonymous cookie ID, enables your browser to be recognised when you visit other websites. Facebook (by Meta) will combine this information with other data from your Facebook account and use it to compile reports on website activity and to provide other services related to website usage, in particular personalised and group-based advertising.
The information automatically collected by Facebook (by Meta) technologies regarding your use of our website is generally transmitted to and stored on a server operated by Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Further information on data processing by Facebook can be found in the Facebook’s (by Meta) privacy policy.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has determined, by means of a decision, that an adequate level of data protection exists: the USA, Canada, Japan, South Korea, New Zealand, the United Kingdom and Argentina.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been obtained.
Our service providers are based in and/or use servers in the following countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil and Mexico. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the following safeguards: the European Commission’s Standard Data Protection Clauses.
Facebook Analytics
As part of Facebook Business Tools, statistics on visitor activity on our website are generated from the data collected via the Facebook Pixel regarding your use of our website. Data processing is carried out on the basis of a data processing agreement with Facebook (by Meta). This analysis is used to optimise the presentation and marketing of our website.
Facebook Ads (Ads Manager)
We use Facebook Ads to advertise this website on Facebook (by Meta) and on other platforms. We determine the parameters of the respective advertising campaign. Facebook (by Meta) is responsible for the precise implementation, in particular for deciding where to place the adverts for individual users. Unless otherwise specified for the individual technologies, data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Joint controllership is limited to the collection of data and its transfer to Meta Platforms Ireland. Subsequent data processing by Meta Platforms Ireland is not covered by this.
Based on the statistics generated via Facebook Pixel regarding visitor activity on our website, we use Facebook Custom Audience to run group-based advertising on Facebook (by Meta), by defining the characteristics of the respective target audience. As part of the extended data matching process carried out to determine the respective target audience (see above), Facebook (by Meta) acts as our data processor.
Based on the pseudonymous cookie ID set by the Facebook Pixel and the data collected regarding your usage behaviour on our website, we use Facebook Pixel to carry out Remarketing personalised advertising.
Via Facebook Pixel Conversions we measure your subsequent usage behaviour for web analytics and event tracking if you have reached our website via a Facebook Ads advertisement. Data processing is carried out on the basis of a data processing agreement with Facebook (by Meta).
7.3 Other providers of web analytics and online marketing services
Use of AdCell retargeting for online marketing
Use of AdCell retargeting for online marketing Through our advertising partner Firstlead GmbH, Rosenfelder Str. 15-16, 10315 Berlin (“adcell”), we advertise this website in search results and on third-party websites. When you visit our website, a retargeting cookie is automatically set by adcell or its partners; this enables interest-based advertising using a pseudonymous cookie ID and based on the pages you have visited. Data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. We determine the parameters of the respective advertising campaign. adcell is responsible for the precise implementation (e.g. deciding on the placement of individual adverts). The data automatically collected by adcell (IP address, time of visit, device and browser information, and information regarding your use of our website) may be combined by adcell with information from other sources and transmitted to adcell’s advertising partners.
Customa
This website uses technologies provided by customa to collect and store data for marketing and optimisation purposes. The provider of this technology is trust in dialog Services GmbH, Merkurring 33-35, 22143 Hamburg, https://www.customa.de. Cookies may be used for this purpose. Cookies are text files that are stored locally in the cache of the website visitor’s web browser. Cookies enable the web browser to be recognised.
Eye-Able Accessibility
Eye-Able® is software developed by Web Inclusion GmbH to ensure that everyone has barrier-free access to information on the internet. The necessary files, such as JavaScript, stylesheets and images, are loaded from an external server for this purpose. When functions are activated, Eye-Able® uses the browser’s local storage to save the settings. All settings are stored locally only and are not transmitted further. To ward off attacks and provide our service in near real time, Eye-Able® uses the Content Delivery Network (CDN) provided by BunnyWay d.o.o. (Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia). This is done for the purpose of fulfilling our contractual obligations to our customers (Article 6(1)(b) of the GDPR) and in the interests of ensuring the secure, fast and efficient provision of our online service by a professional provider (Article 6(1)(f) of the GDPR). All data transmitted and all servers remain within the EU at all times to ensure processing complies with the GDPR. Web Inclusion GmbH does not, at any time, collect or analyse personal user behaviour or other personal data. To ensure processing complies with data protection regulations, Web Inclusion GmbH has entered into data processing agreements with our hosting provider, BunnyWay. Further information can be found in the privacy policies: https://eye-able.com/datenschutz-eye-able/ https://bunny.net/privacy
Neo Commerce
I .We have integrated the Neocom Guided Selling service provided by Neo Commerce GmbH (hereinafter “Neocom”), Max-Bill-Str. 8, 80807 Munich, into our website to provide you with a digital, interactive product advice service. When you start this product advice service, you can find your desired product through a quiz-like, guided process and, at the end, receive a product recommendation which you can then have sent to you by email if you wish.
II. During the consultation, Neocom collects the following browser HTTP information: browser type and version, IP address, and browser language. In addition, a session ID is generated and temporarily stored on your device during the browser session in order to provide the advice. The purpose is to enable the correct and complete display and execution of the digital product advice, similar to a shopping basket function. The legal basis is our legitimate interest pursuant to Article 6(1), first sentence, point (f) of the GDPR (browser query) and Article 6(1), first sentence, point (a) of the GDPR (consent regarding the session ID).
III. Furthermore, a persistent Neocom session ID is stored. This is a purchase tracking tool used to determine whether a purchase has been made with us following the product advice – even across multiple browser sessions. However, this only takes place with your prior consent. The legal basis is therefore Article 6(1), first sentence, point (a) of the GDPR. The session ID is deleted after 365 days at the latest.
IV. Your email address is requested in order to send you product recommendations by email, if you so wish. Neocom uses this address solely for the purpose of sending you the information you have requested. However, this only takes place with your prior consent. The legal basis for this is therefore Article 6(1), first sentence, point (a) of the GDPR. We use the so-called ‘double opt-in procedure’ for registration. Once you have provided your email address, we will send you an email containing a confirmation link to confirm your request to receive the product recommendation. If you click on this confirmation link, your email address will be stored for the purpose of sending the email. If you do not click on the confirmation link within 24 hours, your registration details will be blocked. You may withdraw your consent to the processing of personal data pursuant to Article 6(1), first sentence, point (a) of the GDPR at any time. If you contact us by email, you may object to the storage of your personal data at any time.
V. Neocom uses additional services for product advice. Details of these can be found here.
VI. Use of Neocom product advice within AI-based assistance systems.
It is also possible to use the Neocom product advice service via AI-supported assistance systems. In some cases, interaction takes place via free-text input from users. Personal information may also be transmitted in this context. Please note that the use of free-text input is voluntary and no sensitive information is required. Where technically necessary, this input is processed and stored in accordance with recognised best-practice standards, where appropriate in anonymised or pseudonymised form. The data is encrypted at the access level using state-of-the-art technology (AES-256). Processing is carried out solely for the purpose of providing and optimising the interactive product advice service. In individual cases, this may involve the transfer of data to service providers in third countries outside the EU. In such cases, we ensure that appropriate safeguards are in place in accordance with Article 44 et seq. of the GDPR. Use of the AI-based version is optional; alternatively, a fully click-based experience remains available. The legal basis is your consent in accordance with Article 6(1), first sentence, point (a) of the GDPR.
Use of Hotjar
For the purpose of website analysis, technologies provided by Hotjar Ltd., Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 3155, Malta (“Hotjar”) automatically collect and store data (IP address, time of visit, device and browser information, and information regarding your use of our website), from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. The pseudonymised usage profiles will not be merged with personal data relating to the holder of the pseudonym without separate, explicit consent. Hotjar acts on our behalf.
Use of Vimeo Video Plugin to embed third-party content
To embed third-party content, data (IP address, time of visit, device and browser information) is collected via the Video Plugin provided by Vimeo Inc., 330 West 34th Street, 5th Floor, New York 10011, USA (“Vimeo”), transmitted to Vimeo and subsequently processed by Vimeo. Data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Google Analytics is automatically integrated into the Vimeo Video Plugin. For the purpose of website analysis, Google Analytics automatically collects and stores data (IP address, time of visit, device and browser information, and information regarding your use of our website), from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. Google Analytics is a service provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (‘Google’). The information automatically collected by Google regarding your use of our website is generally transferred to a server operated by Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA, and stored there. If you visit our website from within the EU, your IP address is stored on a server located in the EU for the purpose of deriving location data and is then immediately deleted before the traffic is forwarded to other Google servers for processing. We have no influence over or access to the data processing carried out by Vimeo, including the settings and results of Google Analytics.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by means of a decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
8. Integration of the Trusted Shops Trustbadge/ other widgets
Provided you have given your consent in accordance with Article 6(1)(a) of the GDPR, Trusted Shops Widgets are integrated on this website to display Trusted Shops services (e.g. quality seals, collected reviews) and to offer Trusted Shops products to buyers following an order.
The Trustbadge and the services advertised via it are provided by Trusted Shops SE, Subbelrather Str. 15C, 50823 Cologne ("Trusted Shops"), with whom we are joint controllers under Article 26 of the GDPR. In this privacy notice, we set out below the key terms of the agreement in accordance with Article 26(2) of the GDPR.
As part of the joint responsibility between us and Trusted Shops SE, please contact Trusted Shops in the first instance regarding data protection queries and to exercise your rights, using the contact details provided in the privacy policy. Regardless of this, you may always contact the data controller of your choice. Your enquiry will then, if necessary, be forwarded to the other data controller for a response.
8.1 Data processing when integrating the Trustbadge/ other widgets
The Trustbadge is provided by a US-based CDN provider (Content-Delivery-Network). An adequate level of data protection is ensured in each case by an adequacy decision of the European Commission, which can be accessed here for the USA. Service providers based in the USA are generally certified under the EU-US Data Privacy Framework (DPF). Further information is available here. Where service providers are not certified under the DPF, standard contractual clauses have been agreed as a suitable safeguard.
When the Trustbadge is accessed, the web server automatically stores a so-called server log file, which also contains your IP address, the date and time of access, the volume of data transferred and the requesting provider (access data), and documents the access. The IP address is anonymised immediately after collection, so that the stored data cannot be linked to you personally. The anonymised data is used in particular for statistical purposes and for error analysis.
8.2 Data processing after completion of an order
Provided you have given your consent, once the order has been completed, the Trustbadge will access the order information stored on your device (order total, order number, where applicable the purchased product) as well as your email address, and your email address is hashed using a cryptographic one-way function. The hash value is then transmitted to Trusted Shops together with the order information in accordance with Article 6(1), first sentence, point (a) of the GDPR.
This is to check whether you are already registered for Trusted Shops’ services. If this is the case, further processing will take place in accordance with the contractual agreement between you and Trusted Shops. If you are not yet registered for the services or do not give your consent to automatic recognition via the Trustbadge, you will then be given the option to register manually to use the services or to finalise the terms of your existing user agreement, if applicable.
For this purpose, once your order has been completed, the Trustbadge accesses the following information stored on the device you are using: order total, order number and email address. This is necessary so that we can offer you buyer protection. The data will only be transmitted to Trusted Shops once you have actively opted to take out buyer protection by clicking on the button labelled as such in the so-called Trustcard. If you decide to use the services, further processing is governed by the contractual agreement with Trusted Shops in accordance with Article 6(1)(b) of the GDPR, in order to complete your registration for buyer protection, secure your order and, where applicable, subsequently send you review invitations by email.
Trusted Shops uses service providers in the areas of hosting, monitoring and logging. The legal basis for this is Article 6(1)(f) of the GDPR, for the purpose of ensuring trouble-free operation. In doing so, processing may take place in third countries (the USA, the UK and Israel). An adequate level of data protection is ensured in each case by an adequacy decision of the European Commission, which can be accessed here for the USA, here for the UK and here for Israel. Service providers based in the USA are generally certified under the EU-US Data Privacy Framework (DPF). Further information is available here. Where service providers are not certified under the DPF, standard contractual clauses have been agreed as an appropriate safeguard.
9. Social media
9.1 Social buttons from Facebook (by Meta), Instagram (by Meta)
Our website uses social media buttons from social networks. These are simply embedded in the page as HTML links, meaning that no connection is established with the respective provider’s servers when you visit our website. If you click on one of the buttons, the website of the relevant social network will open in a new browser window There, you can, for example, click the ‘Like’ or ‘Share’ button.
9.2 Our online presence on Facebook (by Meta), Instagram (by Meta), YouTube, Pinterest, LinkedIn, Xing
Provided that you have given your consent to the relevant social media operator in accordance with Article 6(1), first sentence, point (a) of the GDPR, when you visit our online presence on the social media platforms mentioned above, your data will be automatically collected and stored for market research and advertising purposes, from which usage profiles are created using pseudonyms. These may be used, for example, to display advertisements both within and outside the platforms that are presumed to correspond to your interests. Cookies are generally used for this purpose. For detailed information on the processing and use of data by the relevant social media operator, as well as contact details, your rights in this regard and settings to protect your privacy, please refer to the providers’ privacy policies linked below. Should you nevertheless require assistance in this matter, please do not hesitate to contact us.
Facebook (by Meta) is a service provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Meta Platforms Ireland”). The information automatically collected by Meta Platforms Ireland regarding your use of our online presence on Facebook (by Meta) is generally transferred to and stored on a server operated by Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Data processing in connection with a visit to a Facebook (by Meta) fan page is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Further information (including details on Insights data) can be found here.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined that an adequate level of data protection exists: the USA, Canada, Japan, South Korea, New Zealand, the United Kingdom and Argentina.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been obtained.
Our service providers are based in and/or use servers in the following countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil and Mexico.
There is no adequacy decision by the European Commission for these countries. Our cooperation with them is based on these safeguards: the European Commission’s Standard Data Protection Clauses.
Instagram (by Meta) is a service provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Meta Platforms Ireland”). The information automatically collected by Meta Platforms Ireland regarding your use of our online presence on Instagram is generally transmitted to a server operated by Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA, Menlo Park, California 94025, USA and stored there. Data processing in connection with a visit to an Instagram (by Meta) fan page is carried out on the basis of an agreement between joint controllers in accordance with Article 26 of the GDPR. Further information (including details on Insights data) can be found here.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined that an adequate level of data protection exists: the USA, Canada, Japan, South Korea, New Zealand, the United Kingdom and Argentina.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been obtained.
Our service providers are based in and/or use servers in the following countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil and Mexico.
There is no adequacy decision by the European Commission for these countries. Our cooperation with you is based on these safeguards: the European Commission’s Standard Data Protection Clauses.
YouTube is a service provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by Google regarding your use of our online presence on YouTube is generally transmitted to and stored on a server operated by Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by means of a decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
Pinterest is a service provided by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland (“Pinterest”). The information automatically collected by Pinterest regarding your use of our online presence on Pinterest is generally transmitted to and stored on a server operated by Pinterest, Inc., 505 Brannan St., San Francisco, CA 94107, USA.
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has, by means of a decision, determined that an adequate level of data protection exists.
Our service providers are based in and/or use servers in countries outside the EU and the EEA. No adequacy decision has been issued by the European Commission for these countries. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
LinkedIn is a service provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”). The information automatically collected by LinkedIn regarding your use of our online presence on LinkedIn is generally transmitted to and stored on a server operated by LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined that an adequate level of data protection exists: the USA.
The Adequacy Decision for the USA serves as the basis for transfers to third countries, provided that the relevant service provider is certified. Certification has been obtained.
Xing is a service provided by New Work SE, Am Strandkai 1, 20457 Hamburg, Germany.
10. Contact details and your rights
10.1 Your rights
As a data subject, you have the following rights:
- in accordance with Article 15 of the GDPR, the right to request information, to the extent specified therein, regarding your personal data processed by us;
- in accordance with Article 16 of the GDPR, the right to request, without undue delay, the rectification of inaccurate personal data or the completion of your personal data stored by us;
- in accordance with Article 17 of the GDPR, you have the right to request the erasure of your personal data stored by us, unless further processing
- to exercise the right to freedom of expression and information;
- to fulfil a legal obligation;
- for reasons of public interest or
- is necessary for the assertion, exercise or defence of legal claims;
- in accordance with Article 18 of the GDPR, the right to request the restriction of the processing of your personal data, insofar as
- you dispute the accuracy of the data;
- the processing is unlawful, but you object to its erasure;
- we no longer require the data, but you require it to assert, exercise or defend legal claims, or
- you have objected to the processing in accordance with Article 21 of the GDPR;
- in accordance with Article 20 of the GDPR, the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transferred to another controller;
- in accordance with Article 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority for your usual place of residence, your place of work or our company’s registered office.
| Right to object Where we process personal data as explained above to safeguard our legitimate interests, which prevail following a balancing of interests, you may object to this processing with effect for the future. If the processing is carried out for direct marketing purposes, you may exercise this right at any time as described above. Where the processing is carried out for other purposes, you have a right to object only if there are grounds arising from your particular situation. Once you have exercised your right to object, we will no longer process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or where the processing serves to establish, exercise or defend legal claims. This does not apply if the processing is carried out for direct marketing purposes. In that case, we will not process your personal data further for this purpose. |
10.2 Contact details
If you have any questions regarding the collection, processing or use of your personal data, or if you wish to request information, rectification, restriction or erasure of data, or to withdraw consent previously given or object to a specific use of your data, please contact us directly using the contact details provided in our legal notice.
Data Protection Officer:
SHIELD GmbH Martin Vogel
Ohlrattweg 5
25497 Prisdorf
Germany
info@shield-datenschutz.de