Privacy policy

This data protection declaration clarifies the type, scope and purpose of the processing of personal data (hereinafter referred to as "data") within our online offer and the websites, functions and contents connected with it as well as external online presences, such as our Social Media Profile. (hereinafter jointly referred to as "online offer"). With regard to the terms used, e.g. "processing" or "responsible person", we refer to the definitions in Art. 4 of the Basic Data Protection Regulation (DSGVO).

Responsible: Gerhard Grans
Name/Fa.: Winery Grans-Fassian
Street No.: Römerstraße 28
Postcode City, Country: 54340 Leiwen, Germany
Owner: Gerhard Grans Phone
number: +49 6507 - 3170
E-mail address: weingut@grans-fassian.de

types of data processed:

  • inventory data (e.g., names, addresses)
  • Contact details (e.g., e-mail, telephone numbers).
  • Content data (e.g., text entries, photographs, videos).
  • Contract data (e.g., subject matter of the contract, duration, customer category).
  • Payment data (e.g., bank details, payment history).
  • Usage data (e.g., websites visited, interest in content, access times).
  • Meta/communication data (e.g., device information, IP addresses).

Processing of special categories of data (Art. 9 para. 1 DPA):

  • categories of data subjects concerned by the processing operation:
    Customers, interested parties, visitors and users of the online offer, business partners.
  • Visitors and users of the online offer.
Nachfolgend we refer to the persons concerned collectively as "users".
    Purpose of the processing:
  • Provision of the online offer, its contents and shop functions.
  • Provision of contractual services, service and customer care.
  • Responding to contact requests and communication with users.
  • Marketing, advertising and market research.
  • Security measures.
    Last updated: April/2020


1.1 'personal data' shall mean any information relating to an identified or identifiable natural person (hereinafter referred to as 'data subject'); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, a location data, an online identifier (e.g. a cookie) or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person

1.2. Verarbeitung“ ist jeder mit oder ohne Hilfe automatisierter Verfahren ausgeführten Vorgang oder jede solche Vorgangsreihe im Zusammenhang mit personenbezogenen Daten. Der Begriff reicht weit und umfasst praktisch jeden Umgang mit Daten.

1.3 'controller' shall mean the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data

2 Decisive legal
bases

In accordance with Art. 13 DSGVO, we inform you of the legal bases of our data processing. If the legal basis is not stated in the data protection declaration, the following applies: The legal basis for obtaining consent is Art. 6 Para. 1 lit. a and Art. 7 DSGVO, the legal basis for processing for the purpose of fulfilling our services and implementing contractual measures and answering enquiries is Art. 6 Para. 1 lit. b DSGVO, the legal basis for processing for the purpose of fulfilling our legal obligations is Art. 6 Para. 1 lit. c DSGVO, and the legal basis for processing for the purpose of safeguarding our legitimate interests is Art. 6 Para. 1 lit. f DSGVO. In the event that vital interests of the data subject or another natural person require the processing of personal data, Article 6 paragraph 1 letter d DSGVO serves as the legal basis.

3. changes and updates of the data protection declaration
We ask you to inform yourself regularly about the content of our data protection declaration. We will adapt the data protection declaration as soon as changes in the data processing carried out by us make this necessary. We will inform you as soon as the changes make it necessary for you to take action to cooperate (e.g. to give your consent) or any other individual notification.

4. security measures

4.1. Wir treffen nach Maßgabe des Art. 32 DSGVO unter Berücksichtigung des Stands der Technik, der Implementierungskosten und der Art, des Umfangs, der Umstände und der Zwecke der Verarbeitung sowie der unterschiedlichen Eintrittswahrscheinlichkeit und Schwere des Risikos für die Rechte und Freiheiten natürlicher Personen, geeignete technische und organisatorische Maßnahmen, um ein dem Risiko angemessenes Schutzniveau zu gewährleisten; Zu den Maßnahmen gehören insbesondere die Sicherung der Vertraulichkeit, Integrität und Verfügbarkeit von Daten durch Kontrolle des physischen Zugangs zu den Daten, als auch des sie betreffenden Zugriffs, der Eingabe, Weitergabe, der Sicherung der Verfügbarkeit und ihrer Trennung. Des Weiteren haben wir Verfahren eingerichtet, die eine Wahrnehmung von Betroffenenrechten, Löschung von Daten und Reaktion auf Gefährdung der Daten gewährleisten. Ferner berücksichtigen wir den Schutz personenbezogener Daten bereits bei der Entwicklung, bzw. Auswahl von Hardware, Software sowie Verfahren, entsprechend dem Prinzip des Datenschutzes durch Technikgestaltung und durch datenschutzfreundliche Voreinstellungen berücksichtigt (Art. 25 DSGVO).

4.2 Security measures include in particular the encrypted transmission of data between your browser and our server.

5. disclosure and transmission of data

5.1. Sofern wir im Rahmen unserer Verarbeitung Daten gegenüber anderen Personen und Unternehmen (Auftragsverarbeitern oder Dritten) offenbaren, sie an diese übermitteln oder ihnen sonst Zugriff auf die Daten gewähren, erfolgt dies nur auf Grundlage einer gesetzlichen Erlaubnis (z.B. wenn eine Übermittlung der Daten an Dritte, wie an Zahlungsdienstleister, gem. Art. 6 Abs. 1 lit. b DSGVO zur Vertragserfüllung erforderlich ist), Sie eingewilligt haben, eine rechtliche Verpflichtung dies vorsieht oder auf Grundlage unserer berechtigten Interessen (z.B. beim Einsatz von Beauftragten, Hostinganbietern, Steuer-, Wirtschafts- und Rechtsberatern, Kundenpflege-, Buchführungs-, Abrechnungs- und ähnlichen Diensten, die uns eine effiziente und effektive Erfüllung unserer Vertragspflichten, Verwaltungsaufgaben und Pflichten erlauben).

5.2 If we commission third parties to process data on the basis of a so-called "contract processing agreement", this is done on the basis of Art. 28 DSGVO.

6. transfers to third countries

Sofern wir Daten in einem Drittland (d.h. außerhalb der Europäischen Union (EU) oder des Europäischen Wirtschaftsraums (EWR)) verarbeiten oder dies im Rahmen der Inanspruchnahme von Diensten Dritter oder Offenlegung, bzw. Übermittlung von Daten an Dritte geschieht, erfolgt dies nur, wenn es zur Erfüllung unserer (vor)vertraglichen Pflichten, auf Grundlage Ihrer Einwilligung, aufgrund einer rechtlichen Verpflichtung oder auf Grundlage unserer berechtigten Interessen geschieht. Vorbehaltlich gesetzlicher oder vertraglicher Erlaubnisse, verarbeiten oder lassen wir die Daten in einem Drittland nur beim Vorliegen der besonderen Voraussetzungen der Art. 44 ff. DSGVO verarbeiten. D.h. die Verarbeitung erfolgt z.B. auf Grundlage besonderer Garantien, wie der offiziell anerkannten Feststellung eines der EU entsprechenden Datenschutzniveaus (z.B. für die USA durch das „Privacy Shield“) oder Beachtung offiziell anerkannter spezieller vertraglicher Verpflichtungen (so genannte „Standardvertragsklauseln“).

7.rights of data subjects

7.1. Sie haben das Recht, eine Bestätigung darüber zu verlangen, ob betreffende Daten verarbeitet werden und auf Auskunft über diese Daten sowie auf weitere Informationen und Kopie der Daten entsprechend Art. 15 DSGVO.

7.2. you have accordingly. Art. 16 DSGVO the right to request the completion of data concerning you or the correction of incorrect data concerning you.

7.3 In accordance with Art. 17 DSGVO, you have the right to demand that the data in question be deleted immediately, or alternatively, in accordance with Art. 18 DSGVO, to demand a restriction on the processing of the data.

7.4 You have the right to request that the data concerning you which you have provided us with be made available to us in accordance with art. 20 of the DSGVO and to request that it be communicated to other persons responsible.

7.5 You also have the right to lodge a complaint with the competent supervisory authority pursuant to Art. 77 DSGVO.

8.right of revocatio
n

You have the right to revoke consents granted in accordance with Art. 7 para. 3 DSGVO with effect for the future.

9.right of objectio
n

You can object to the future processing of data concerning you in accordance with Art. 21 DSGVO at any time. The objection may in particular be made against processing for the purposes of direct advertising.

10.cookies and right of objection for direct advertising

10.1. Als „Cookies“ werden kleine Dateien bezeichnet, die auf Rechnern der Nutzer gespeichert werden. Innerhalb der Cookies können unterschiedliche Angaben gespeichert werden. Ein Cookie dient primär dazu, die Angaben zu einem Nutzer (bzw. dem Gerät auf dem das Cookie gespeichert ist) während oder auch nach seinem Besuch innerhalb eines Onlineangebotes zu speichern. Als temporäre Cookies, bzw. „Session-Cookies“ oder „transiente Cookies“, werden Cookies bezeichnet, die gelöscht werden, nachdem ein Nutzer ein Onlineangebot verlässt und seinen Browser schließt. In einem solchen Cookie kann z.B. der Inhalt eines Warenkorbs in einem Onlineshop oder ein Login-Status gespeichert werden. Als „permanent“ oder „persistent“ werden Cookies bezeichnet, die auch nach dem Schließen des Browsers gespeichert bleiben. So kann z.B. der Login-Status gespeichert werden, wenn die Nutzer diese nach mehreren Tagen aufsuchen. Ebenso können in einem solchen Cookie die Interessen der Nutzer gespeichert werden, die für Reichweitenmessung oder Marketingzwecke verwendet werden. Als „Third-Party-Cookie“ werden Cookies von anderen Anbietern als dem Verantwortlichen, der das Onlineangebot betreibt, bezeichnet (andernfalls, wenn es nur dessen Cookies sind spricht man von „First-Party Cookies“).

10.2 We use temporary and permanent cookies and explain this in our privacy policy.
Falls the users do not want cookies to be stored on their computer, they are asked to deactivate the corresponding option in the system settings of their browser. Stored cookies can be deleted in the system settings of the browser. The exclusion of cookies can lead to functional restrictions of this online offer.

10.3 A general objection to the use of cookies used for online marketing purposes can be declared for many of the services, especially in the case of tracking, via the US site http://www.aboutads.info/choices/ or the EU site http://www.youronlinechoices.com/. Furthermore, the storage of cookies can be achieved by deactivating them in the browser settings. Please note that in this case not all functions of this online offer can be used.

11.1 The data

processed by us will be deleted or limited in their processing in accordance with articles 17 and 18 DSGVO. Unless expressly stated in this data protection declaration, the data stored by us will be deleted as soon as they are no longer required for their intended purpose and the deletion does not conflict with any statutory storage obligations. If the data are not deleted because they are required for other and legally permissible purposes, their processing will be restricted. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.

11.2. Deutschland: Nach gesetzlichen Vorgaben erfolgt die Aufbewahrung insbesondere für 6 Jahre gemäß § 257 Abs. 1 HGB (Handelsbücher, Inventare, Eröffnungsbilanzen, Jahresabschlüsse, Handelsbriefe, Buchungsbelege, etc.) sowie für 10 Jahre gemäß § 147 Abs. 1 AO (Bücher, Aufzeichnungen, Lageberichte, Buchungsbelege, Handels- und Geschäftsbriefe, für Besteuerung relevante Unterlagen, etc


12.1 We process the data of our customers in the context of the order procedures in our
online
shop, in order to enable them to select and order the selected products and services, as well as their payment and delivery, or execution.

12.2. Zu den verarbeiteten Daten gehören Bestandsdaten, Kommunikationsdaten, Vertragsdaten, Zahlungsdaten und zu den betroffenen Personen unsere Kunden, Interessenten und sonstige Geschäftspartner. Die Verarbeitung erfolgt zum Zweck der Erbringung von Vertragsleistungen im Rahmen des Betriebs eines Onlineshops, Abrechnung, Auslieferung und der Kundenservices. Hierbei setzen wir Session Cookies für die Speicherung des Warenkorb-Inhalts und permanente Cookies für die Speicherung des Login-Status ein.

12.3 Processing shall be carried out on the basis of Art. 6 para. 1 lit. b (execution of order processes) and c (legally required archiving) DSGVO. In this context, the information marked as required is required for the establishment and fulfilment of the contract. We disclose the data to third parties only within the scope of delivery, payment or within the scope of the legal permits and obligations to legal advisors and authorities. The data will only be processed in third countries if this is necessary for the fulfilment of the contract (e.g. on customer request for delivery or payment).

12.4 Users can optionally create a user account, in particular by viewing their orders. During the registration process, the required mandatory data will be provided to the users. The user accounts are not public and cannot be indexed by search engines. If users have terminated their user account, their data will be deleted with regard to the user account, subject to their safekeeping is necessary for reasons of commercial or tax law in accordance with Art. 6 Para. 1 lit. c DSGVO. Data in the customer account will remain until its deletion with subsequent archiving in case of a legal obligation. It is the responsibility of the users to save their data in case of termination before the end of the contract.

12.5 Within the scope of registration and renewed logins and use of our online services, we store the IP address and the time of the respective user action. The storage is based on our legitimate interests, as well as the user's need for protection against misuse and other unauthorized use. As a matter of principle, this data is not passed on to third parties unless it is necessary to pursue our claims or there is a legal obligation to do so in accordance with Art. 6 Para. 1 lit. c DSGVO.

12.6 Deletion takes place after expiry of statutory warranty and comparable obligations, the necessity of data storage is reviewed every three years; in the case of statutory archiving obligations, deletion takes place after expiry (end of commercial law (6 years) and tax law (10 years) storage obligation); data in the customer account remain until its deletion.

13.economic analyses and market research

13.1. Um unser Geschäft wirtschaftlich betreiben, Markttendenzen, Kunden- und Nutzerwünsche erkennen zu können, analysieren wir die uns vorliegenden Daten zu Geschäftsvorgängen, Verträgen, Anfragen, etc. Wir verarbeiten dabei Bestandsdaten, Kommunikationsdaten, Vertragsdaten, Zahlungsdaten, Nutzungsdaten, Metadaten auf Grundlage des Art. 6 Abs. 1 lit. f. DSGVO, wobei zu den betroffenen Personen Kunden, Interessenten, Geschäftspartner, Besucher und Nutzer des Onlineangebotes gehören. Die Analysen erfolgen zum Zweck Betriebswirtschaftliche Auswertungen, des Marketings und der Marktforschung. Dabei können wir die Profile der registrierten Nutzer mit Angaben z.B. zu deren Kaufvorgängen berücksichtigen. Die Analysen dienen uns zur Steigerung der Nutzerfreundlichkeit, der Optimierung unseres Angebotes und der Betriebswirtschaftlichkeit. Die Analysen dienen alleine uns und werden nicht extern offenbart, sofern es sich nicht um anonyme Analysen mit zusammengefassten Werten handelt.

13.2 If these analyses or profiles are personal, they will be deleted or made anonymous upon termination by the user, otherwise after two years from conclusion of the contract. In all other respects, the macroeconomic analyses and general trend determinations are prepared anonymously wherever possible.

14.contact and customer service

14.1. Bei der Kontaktaufnahme mit uns (per Kontaktformular oder E-Mail) werden die Angaben des Nutzers zur Bearbeitung der Kontaktanfrage und deren Abwicklung gem. Art. 6 Abs. 1 lit. a) DSGVO verarbeitet.

14.2 The information provided by users may be stored in our Customer Relationship Management System ("CRM System") or comparable enquiry organisation.

14.3 We delete the requests if they are no longer necessary. We review the necessity every two years; we permanently store inquiries from customers who have a customer account and refer to the information on the customer account for deletion. Furthermore, the statutory archiving obligations apply.

15.collection of access data and log files

15.1. Wir erheben auf Grundlage unserer berechtigten Interessen im Sinne des Art. 6 Abs. 1 lit. f. DSGVO Daten über jeden Zugriff auf den Server, auf dem sich dieser Dienst befindet (sogenannte Serverlogfiles). Zu den Zugriffsdaten gehören Name der abgerufenen Webseite, Datei, Datum und Uhrzeit des Abrufs, übertragene Datenmenge, Meldung über erfolgreichen Abruf, Browsertyp nebst Version, das Betriebssystem des Nutzers, Referrer URL (die zuvor besuchte Seite), IP-Adresse und der anfragende Provider. Die Daten werden gelöscht, sobald sie für die Erreichung des Zweckes ihrer Erhebung nicht mehr erforderlich sind. Im Falle der Erfassung der Daten zur Bereitstellung der Website ist dies der Fall, wenn die jeweilige Sitzung beendet ist.

15.2 For security reasons (e.g. for the investigation of abuse or fraud), log file information is stored for a maximum of seven days and then deleted. Data whose further storage is required for evidential purposes are excluded from deletion until the respective incident has been finally clarified.

16.online presence in social media

16.1. Wir unterhalten auf Grundlage unserer berechtigten Interessen im Sinne des Art. 6 Abs. 1 lit. f. DSGVO Onlinepräsenzen innerhalb sozialer Netzwerke und Plattformen, um mit den dort aktiven Kunden, Interessenten und Nutzern kommunizieren und sie dort über unsere Leistungen informieren zu können. Beim Aufruf der jeweiligen Netzwerke und Plattformen gelten die Geschäftsbedingungen und die Datenverarbeitungsrichtlinien deren jeweiligen Betreiber.

16.2 Unless otherwise stated in our data protection declaration, we process the data of users if they communicate with us within social networks and platforms, e.g. write articles on our online presences or send us messages.

17. facebook

17.1 Furthermore, when using the Facebook Pixel, we use the additional function "extended matching" (here, data such as telephone numbers, email addresses or Facebook IDs of users) to create target groups ("Custom Audiences" or "Look Alike Audiences") to Facebook (encrypted). Further notes on "extended matching": https://www.facebook.com/business/help/611774685654668).
We also use the "Custom Audiences from File" procedure of the social network Facebook, Inc. In this case, the email addresses of the newsletter recipients are uploaded to Facebook. The upload process is encrypted. The upload is used solely to determine recipients of our Facebook ads. We want to ensure that the ads are only displayed to users who have an interest in our information and services.
Opt-Out Note: Please note that Facebook does not offer an opt-out at the time this pattern is created and you will need to implement it yourself. If you do not, you must remove this passage. The implementation can be done e.g. by using Javascript (setting the opt-out link) and when loading the page via PHP (which checks whether the opt-out cookie has been set and only loads the Facebook pixel in case of a negative result). If a user visits the website, it must be checked whether the "Opt-Out" cookie has been set. If so, the "Facebook pixel" must not be loaded.
Please include the following addition in case of your own opt-out:
To prevent the collection of your data by means of the Facebook pixel on our website, please click the following link: Facebook-Opt-Out Note: When you click the link, an "Opt-Out" cookie is stored on your device. If you delete the cookies in this browser, you will need to click the link again. Furthermore, the opt-out only applies within the browser you are using and only within our web domain where the link was clicked.
20. Facebook-, Custom Audiences and Facebook-Marketing-Dienste
20.1. Within our online offer, due to our legitimate interests in analysis, optimization and economic operation of our online offer and for these purposes the so-called "Facebook pixel" of the social network Facebook, which is operated by Facebook Inc, 1 Hacker Way, Menlo Park, CA 94025, USA, or if you are resident in the EU, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Facebook").

17.2 Facebook is certified under the Privacy Shield Agreement and thus offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active).

17.3 With the help of the Facebook pixel, Facebook is on the one hand able to determine the visitors of our online offer as a target group for the presentation of ads (so-called "Facebook ads"). Accordingly, we use the Facebook Pixel in order to display the Facebook Ads placed by us only to those Facebook users who have also shown an interest in our online offering or who exhibit certain characteristics (e.g. interests in certain topics or products determined on the basis of the websites visited) that we transmit to Facebook (so-called "custom audiences"). With the help of the Facebook pixel, we also want to ensure that our Facebook Ads correspond to the potential interest of users and do not appear to be annoying. With the help of the Facebook Pixel, we can also track the effectiveness of Facebook Ads for statistical and market research purposes by seeing whether users are redirected to our website after clicking on a Facebook Ad (so-called "conversion").

17.4 The processing of data by Facebook is carried out within the framework of Facebook's Data Use Policy. Accordingly, general information on the display of Facebook Ads, in the Facebook Data Usage Policy: https://www.facebook.com/policy.php. Specific information and details about the Facebook pixel and its functionality can be found in the Facebook help section: https://www.facebook.com/business/help/651294705016616.

17.5 You may object to the collection by the Facebook Pixel and use of your data to display Facebook Ads. To control what types of ads are displayed to you within Facebook, you can go to the page set up by Facebook and follow the instructions for usage-based advertising settings: https://www.facebook.com/settings?tab=ads. The settings are platform-independent, which means they apply to all devices, such as desktop computers or mobile devices. r>

17.6 You may also object to the use of cookies for audience measurement and advertising purposes via the Network Advertising Initiative opt-out page (http://optout.networkadvertising.org/) and additionally via the US website (http://www.aboutads.info/choices) or the European website (http://www.youronlinechoices.com/uk/your-ad-choices/).

18. facebook social plugins

18.1. Wir nutzen auf Grundlage unserer berechtigten Interessen (d.h. Interesse an der Analyse, Optimierung und wirtschaftlichem Betrieb unseres Onlineangebotes im Sinne des Art. 6 Abs. 1 lit. f. DSGVO) Social Plugins (“Plugins”) des sozialen Netzwerkes facebook.com, welches von der Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Irland betrieben wird (“Facebook”). Die Plugins können Interaktionselemente oder Inhalte (z.B. Videos, Grafiken oder Textbeiträge) darstellen und sind an einem der Facebook Logos erkennbar (weißes „f“ auf blauer Kachel, den Begriffen “Like”, “Gefällt mir” oder einem „Daumen hoch“-Zeichen) oder sind mit dem Zusatz “Facebook Social Plugin” gekennzeichnet. Die Liste und das Aussehen der Facebook Social Plugins kann hier eingesehen werden: https://developers.facebook.com/docs/plugins/.

18.2 Facebook is certified under the Privacy Shield Agreement and thus offers a guarantee to comply with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active).

18.3 If a user calls up a function of this online offer that contains such a plugin, his device establishes a direct connection with the Facebook servers. The content of the plugin is transmitted by Facebook directly to the user's device and integrated into the online offer by the user. User profiles can be created from the processed data. We therefore have no influence on the scope of the data that Facebook collects with the help of this plugin and therefore inform the users according to our state of knowledge.

18.4 By integrating the plugins, Facebook receives the information that a user has called up the corresponding page of the online offer. If the user is logged in to Facebook, Facebook can assign the visit to his or her Facebook account. If users interact with the plugins, for example, by pressing the Like button or making a comment, the corresponding information is transmitted directly from your device to Facebook and stored there. If a user is not a member of Facebook, it is still possible for Facebook to find out his or her IP address and store it. According to Facebook, only an anonymized IP address is stored in Germany.

18.5 The purpose and scope of data collection and the further processing and use of the data by Facebook, as well as the relevant rights and setting options to protect the privacy of users, can be found in the Facebook privacy policy: https://www.facebook.com/about/privacy/.

18.6 If a user is a Facebook member and does not want Facebook to collect data about him or her via this online offer and link it with his or her membership data stored on Facebook, he or she must log out of Facebook and delete his or her cookies before using our online offer. Further settings and objections to the use of data for advertising purposes are possible within the Facebook profile settings: https://www.facebook.com/settings?tab=ads or via the US-American page http://www.aboutads.info/choices/ or the EU page http://www.youronlinechoices.com/. The settings are platform-independent, i.e. they are adopted for all devices, such as desktop computers or mobile devices.

19 Google Analytics
19.1 On
the basis of our legitimate interests (i.e. interest in the
analysis, optimisation and economic operation of our
online offer within the meaning of Art. 6 Paragraph 1 lit. f. DSGVO) we use Google
Analytics, a web analysis service of Google LLC ("Google"). Google
uses cookies. The information generated by the cookie about the
use of the website by the user is usually transferred to
a Google server in the USA and stored there.

19.2
Google is certified under the Privacy Shield Agreement and
thus offers a guarantee that it complies with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAItatus=Active).

19.3
Google will use this information on our behalf in order to evaluate the
use of our website by users, to compile
reports
on the activities within this website and to provide us with further services associated with the use of this website and the use of the
Internet.
In doing so, pseudonymous user profiles of the
users can be created from the processed data.

19.4 We use Google Analytics only with
activated IP anonymization. This means that the IP address of
users is shortened by Google within member states of the European
Union or in other states that are party to the Agreement on the
European Economic Area. Only in exceptional cases is the
full IP address transferred to a Google server in the USA and shortened
there.

19.5 The IP
address transmitted by the user's browser is not merged with other data from Google.
Users can prevent the storage of cookies by adjusting their browser software accordingly
; users can
also prevent the collection of data generated by the cookie and related to their
use of the online offer to Google and the
processing of this data by Google by downloading and installing
the browser plugin available under the
following link: https://tools.google.com/dlpage/gaoptout?hl=de.

19.6
Further information on Google's use of data, setting and
objection options can be found on the websites of Google: https://www.google.com/intl/de/policies/privacy/partners ("Data use by Google when you use the websites or apps of our partners"), https://policies.google.com/technologies/ads ("Data use for advertising purposes"), https://adssettings.google.com/authenticated ("Manage information that Google uses to show you advertising").

20. communication by mail, e-mail, fax or telephone

20.1 Wir nutzen für die Geschäftsabwicklung und für Marketingzwecke Fernkommunikationsmittel, wie z.B. Post, Telefon oder E-Mail. Dabei verarbeiten wir Bestandsdaten, Adress- und Kontaktdaten sowie Vertragsdaten von Kunden, Teilnehmern, Interessenten und Kommunikationspartner.

20.2 The processing is based on Art. 6 para. 1 letter a, Art. 7 DSGVO, Art. 6 para. 1 letter f DSGVO in connection with legal requirements for advertising communications. Contact will only be established with the consent of the contact partners or within the scope of the legal permissions and the processed data will be deleted as soon as they are not required and otherwise with objection/ revocation or discontinuation of the basis of entitlement or legal archiving obligations.

21. shipping service provider

21.1 The newsletter is sent by means of CleverReach GmbH & Co. KG, Mühlenstr. 43, 26180 Rastede, Germany, hereinafter referred to as "shipping service provider". You can view the data protection regulations of the mail-order service provider here: https://www.cleverreach.com/de/datenschutz/.
Dispatch service provider: Newsletters are sent by means of "MailChimp", a newsletter dispatch platform of the US provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA. The data protection regulations of the mail service provider can be viewed here: https://mailchimp.com/legal/privacy/. The Rocket Science Group LLC d/b/a MailChimp is certified under the Privacy Shield Agreement and thus offers a guarantee to comply with the European level of data protection (https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAGtatus=Active).

21.2 Content of the newsletter: We send newsletters, e-mails and other electronic notifications containing advertising information (hereinafter "newsletter") only with the consent of the recipients or a legal permission. Insofar as the contents of the newsletter are specifically described in the context of a registration for the newsletter, they are decisive for the consent of the users. Furthermore, our newsletters contain information about our products, offers, promotions and our company.

21.3 Double-Opt-In and logging: The registration for our newsletter is done in a so-called Double-Opt-In procedure. This means that after registration you will receive an e-mail asking you to confirm your registration. This confirmation is necessary so that nobody can register with foreign e-mail addresses. The newsletter registrations are logged in order to be able to prove the registration process according to the legal requirements. This includes the storage of the registration and confirmation time as well as the IP address. Changes to your data stored by the shipping service provider are also logged.

21.4 Dispatch service provider: Newsletters are sent by means of "MailChimp", a newsletter dispatch platform of the US provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA. The data protection regulations of the mail service provider can be viewed here: https://mailchimp.com/legal/privacy/. The Rocket Science Group LLC d/b/a MailChimp is certified under the Privacy Shield Agreement and thus offers a guarantee to comply with the European level of data protection (https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAGtatus=Active).

21.5 If we use a shipping service provider, the shipping service provider may, according to its own information, use this data in pseudonymous form, i.e. without allocation to a user, to optimize or improve its own services, e.g. for technical optimization of the sending and presentation of newsletters or for statistical purposes to determine from which countries the recipients come. However, the dispatch service provider does not use the data of our newsletter recipients to write to them itself or pass them on to third parties.

21.6. registration data: To subscribe to the newsletter, it is sufficient to enter your e-mail address. Optionally, we ask you to enter a name in order to address you personally in the newsletter.

21.7 Success measurement - The newsletters contain a so-called "web beacon", i.e. a pixel-sized file that is retrieved from our server when the newsletter is opened or, if we use a mailing service provider, from their server. Within the scope of this retrieval, technical information such as information on the browser and your system, as well as your IP address and time of retrieval are initially collected. This information is used for the technical improvement of the services based on the technical data or the target groups and their reading behaviour based on their retrieval locations (which can be determined by means of the IP address) or the access times. Statistical surveys also include determining whether newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to individual newsletter recipients. However, it is neither our intention nor, if used, that of the dispatch service provider to observe individual users. The evaluations serve us much more to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.

21.8. Germany: The dispatch of the newsletter and the measurement of success are based on the consent of the recipients in accordance with Art. 6 Para. 1 lit. a, Art. 7 DSGVO in conjunction with § 7 Para. 2 No. 3 UWG or on the basis of the legal permission in accordance with § 7 Para. 3 UWG.

21.9 The logging of the registration procedure is based on our legitimate interests in accordance with Art. 6 Para. 1 letter f DSGVO and serves as proof of consent to receive the newsletter.

21.10. Newsletter recipients can cancel the receipt of our newsletter at any time, i.e. revoke their consent. A link to cancel the newsletter can be found at the end of each newsletter. At the same time their consent to the performance measurement expires. A separate revocation of the performance measurement is unfortunately not possible, in which case the entire newsletter subscription must be cancelled. When you unsubscribe from the newsletter, your personal data will be deleted, unless their storage is legally required or justified, in which case their processing will be limited to these exceptional purposes only. In particular, we may store the unsubscribed e-mail addresses for up to three years on the basis of our legitimate interests before we delete them for the purposes of sending the newsletter, in order to be able to prove that we have previously given our consent. The processing of this data is limited to the purpose of a possible defence against claims. An individual request for deletion is possible at any time, provided that the former existence of a consent is confirmed at the same time.

22. integration of third party services and content

22.1. Wir setzen innerhalb unseres Onlineangebotes auf Grundlage unserer berechtigten Interessen (d.h. Interesse an der Analyse, Optimierung und wirtschaftlichem Betrieb unseres Onlineangebotes im Sinne des Art. 6 Abs. 1 lit. f. DSGVO) Inhalts- oder Serviceangebote von Drittanbietern ein, um deren Inhalte und Services, wie z.B. Videos oder Schriftarten einzubinden (nachfolgend einheitlich bezeichnet als “Inhalte”). Dies setzt immer voraus, dass die Drittanbieter dieser Inhalte, die IP-Adresse der Nutzer wahrnehmen, da sie ohne die IP-Adresse die Inhalte nicht an deren Browser senden könnten. Die IP-Adresse ist damit für die Darstellung dieser Inhalte erforderlich. Wir bemühen uns nur solche Inhalte zu verwenden, deren jeweilige Anbieter die IP-Adresse lediglich zur Auslieferung der Inhalte verwenden. Drittanbieter können ferner so genannte Pixel-Tags (unsichtbare Grafiken, auch als “Web Beacons” bezeichnet) für statistische oder Marketingzwecke verwenden. Durch die “Pixel-Tags” können Informationen, wie der Besucherverkehr auf den Seiten dieser Website ausgewertet werden. Die pseudonymen Informationen können ferner in Cookies auf dem Gerät der Nutzer gespeichert werden und unter anderem technische Informationen zum Browser und Betriebssystem, verweisende Webseiten, Besuchszeit sowie weitere Angaben zur Nutzung unseres Onlineangebotes enthalten, als auch mit solchen Informationen aus anderen Quellen verbunden werden können.

22.2. The following presentation offers an overview of third party providers and their content, along with links to their privacy policies, further information on the processing of data and, in some cases already mentioned here, the possibility to object (so-called opt-out) enthalten
- If our customers use the payment services of third parties (e.g. PayPal or Sofortüberweisung), the terms and conditions and the privacy policy of the respective third party providers apply, which can be accessed within the respective websites or transaction applications.

- External Fonts from Google, LLC., https://www.google.com/fonts ("Google Fonts"). Google Fonts are integrated by a server call to Google (usually in the USA). Privacy policy: https://policies.google.com/privacy, Opt-Out: https://adssettings.google.com/authenticated.

- Maps of the service "Google Maps" provided by the third-party provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: https://www.google.com/policies/privacy/, opt-out: https://www.google.com/settings/ads/.
- Videos from the "YouTube" platform of the third-party provider Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: https://www.google.com/policies/privacy/, Opt-Out: https://www.google.com/settings/ads/.

- Within our online offer functions of the service Google+ are integrated. These functions are offered by the third-party provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. If you are logged in to your Google+ account, you can link the contents of our pages to your Google+ profile by clicking the Google+ button. This allows Google to associate your visit to our pages with your user account. We would like to point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data or its use by Google+. Privacy policy: https://policies.google.com/privacy, Opt-Out: https://adssettings.google.com/authenticated.

- Within our online offer functions of the service Instagram are integrated. These functions are offered by Instagram Inc, 1601 Willow Road, Menlo Park, CA, 94025, USA. If you are logged in to your Instagram account, you can link the content of our pages to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to our site with your account. We would like to point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data or its use by Instagram. Privacy policy: http://instagram.com/about/legal/privacy/.

- We use social plugins from the Pinterest social network, which is operated by Pinterest Inc. 635 High Street, Palo Alto, CA, 94301, USA ("Pinterest"). When you access a page that contains such a plugin, your browser establishes a direct connection to the servers of Pinterest. The plugin transfers protocol data to the Pinterest server in the USA. This log data may include your IP address, the address of the websites you visit that also contain Pinterest functions, the type and settings of your browser, the date and time of your request, your use of Pinterest and cookies. Privacy Policy: https://about.pinterest.com/de/privacy-policy.

- Functions of the service or the Hotjar platform are integrated within our online offer (hereinafter referred to as "Hotjar").
Wir use Hotjar in order to better understand the needs of our users and to optimize the offer on this website. With the help of Hotjar's technology, we gain a better understanding of our users' experiences (e.g. how much time users spend on which pages, which links they click, what they like and what they don't like, etc.) and this helps us to tailor our offering to our users' feedback. Hotjar uses cookies and other technologies to collect information about our users' behavior and about their end devices (in particular, IP address of the device (only collected and stored in anonymous form), screen size, device type (Unique Device Identifiers), information about the browser used, location (country only), language preferred to view our website). Hotjar stores this information in a pseudonymous user profile. The information is not used by Hotjar or by us to identify individual users, nor is it merged with other data about individual users. The legal basis is Art. 6 para. 1 p. 1 lit. f DSGVO. For further information, please see Hotjar's privacy policy: https://www.hotjar.com/legal/policies/privacy.
You can object to the storage of a user profile and information about your visit to our website by Hotjar and to the setting of Hotjar tracking cookies on other websites via this link: https://www.hotjar.com/legal/compliance/opt-out