Data Protection


Privacy Policy

1) Introduction and contact details of the person responsible

1.1 We are pleased that you visit our website and thank you for your interest. Below we inform you about the handling of your personal data when using our website. Personal data means all data with which you can be personally identified.

1.2 The person responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is iesse Schuh GmbH, Schweppenkamp 8, 38644 Goslar, Germany, Tel.: +49 (0)5321-3709-0, Fax: +49 (0)5321-351479, E-Mail: info@haflinger.com. The person responsible for processing personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.

1.3 The person responsible has appointed a data protection officer, who can be reached as follows: "Dr. Sebastian Kraska, IITR Datenschutz GmbH, Marienplatz 2, 80331 Munich, skraska@iitr.de"

2) Data collection when visiting our website

2.1 When using our website for informational purposes only, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the page server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time at the time of access
  • Amount of data sent in bytes
  • Source/referral from which you accessed the site
  • Browser used
  • Operating system used
  • Used IP address (if applicable: in anonymized form)

The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. No data is passed on or used otherwise. However, we reserve the right to review the server log files retrospectively if there are concrete indications of unlawful use.

2.2 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the person responsible). You can recognize an encrypted connection by the "https://" prefix and the lock symbol in your browser's address bar.

3) Cookies

To make visiting our website attractive and to enable the use of certain functions, we use cookies, i.e., small text files that are stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called "session cookies"), while others remain on your device longer and allow the storage of site settings (so-called "persistent cookies"). In the latter case, you can find the storage duration in the overview of your web browser's cookie settings.

If personal data is processed through individual cookies used by us, the processing takes place in accordance with Art. 6 para. 1 lit. b GDPR either for the performance of the contract, according to Art. 6 para. 1 lit. a GDPR in the case of given consent, or according to Art. 6 para. 1 lit. f GDPR to protect our legitimate interests in the best possible functionality of the website as well as a customer-friendly and effective design of the site visit.

You can set your browser to inform you about the setting of cookies and decide individually whether to accept them or to exclude the acceptance of cookies for certain cases or in general.

Please note that if you do not accept cookies, the functionality of our website may be limited.

4) Contact

4.1 Own review reminder

Only based on your explicit consent pursuant to Art. 6 para. 1 lit. a GDPR do we use your email address to send a one-time reminder to submit a review of your order. You can revoke your consent at any time by sending a message to the person responsible for data processing.

4.2 In the context of contacting us (e.g., via contact form or email), personal data is processed solely for the purpose of handling and responding to your request and only to the extent necessary for this purpose.

The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Art. 6 para. 1 lit. f GDPR. If your contact is aimed at a contract, the additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted when the circumstances indicate that the matter in question has been conclusively resolved and provided that no statutory retention obligations oppose this.

5) Comment function

As part of the comment function on this website, in addition to your comment, information about the time the comment was created and the commentator name you chose will be stored and published on this website. Furthermore, your IP address is logged and stored. This storage of the IP address is done for security reasons and in case the person concerned violates the rights of third parties or posts unlawful content through a comment. We need your email address to contact you if a third party objects to your published content as unlawful.

The legal bases for storing your data are Art. 6 para. 1 lit. b and f GDPR. We reserve the right to delete comments if they are reported as unlawful by third parties.

6) Data processing when opening a customer account

According to Art. 6 para. 1 lit. b GDPR, personal data will continue to be collected and processed to the extent necessary if you provide it to us when opening a customer account. Which data is required for account opening can be found in the input mask of the corresponding form on our website.

You can delete your customer account at any time by sending a message to the above address of the person responsible. After deleting your customer account, your data will be deleted provided that all contracts concluded through it have been fully processed, no legal retention periods prevent this, and we have no legitimate interest in further storage.

7) Use of customer data for direct advertising

7.1 Sign up for our email newsletter

When you sign up for our email newsletter, we regularly send you information about our offers. The only mandatory information for sending the newsletter is your email address. Providing additional data is voluntary and is used to address you personally. For sending the newsletter, we use the so-called double opt-in procedure, which ensures that you only receive the newsletter after you have explicitly confirmed your consent to receive the newsletter by clicking a verification link sent to the specified email address.

By activating the confirmation link, you give us your consent to use your personal data according to Art. 6 para. 1 lit. a GDPR. We store the IP address registered by your Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any possible misuse of your email address at a later time. The data we collect when registering for the newsletter is used strictly for the intended purpose.

You can unsubscribe from the newsletter at any time via the designated link in the newsletter or by sending a corresponding message to the responsible party named at the beginning. After unsubscribing, your email address will be promptly deleted from our newsletter distribution list unless you have explicitly consented to further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this statement.

7.2 MailChimp

Our email newsletters are sent via this provider: The Rocket Science Group, LLC d/b/a MailChimp, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA

Based on our legitimate interest in effective and user-friendly newsletter marketing, we forward the data you provide when registering for the newsletter according to Art. 6 para. 1 lit. f GDPR to this provider so that they can handle the newsletter dispatch on our behalf.

Subject to your explicit consent according to Art. 6 para. 1 lit. a GDPR, the provider also conducts a statistical success evaluation of newsletter campaigns using web beacons or tracking pixels in the sent emails, which can measure open rates and specific interactions with the newsletter content. Device information (e.g., time of access, IP address, browser type, and operating system) is also collected and evaluated but not merged with other data sets.

You can revoke your consent to newsletter tracking at any time with effect for the future.

We have concluded a data processing agreement with the provider that protects the data of our website visitors and prohibits sharing with third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

7.3 Product availability notification by email

For temporarily unavailable items, you can sign up to receive email product availability notifications. We will send you a one-time email notification about the availability of the item you selected. The only mandatory information for sending this notification is your email address. Providing additional data is voluntary and may be used to address you personally. For sending the email, we use the so-called double opt-in procedure, which ensures that you only receive a notification after you have explicitly confirmed your consent by clicking a verification link sent to the specified email address.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 para. 1 lit. a GDPR. In doing so, we store the IP address registered by your Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any possible misuse of your email address at a later time. The data collected by us when registering for our email notification service for product availability is used strictly for the intended purpose.

You can unsubscribe from availability notifications at any time by sending a corresponding message to the responsible party named at the beginning. After deregistration, your email address will be immediately deleted from our distribution list set up for this purpose, unless you have explicitly consented to further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this declaration.

8) Data processing for order processing

8.1 To the extent necessary for contract processing for delivery and payment purposes, the personal data collected by us will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 para. 1 lit. b GDPR.

If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we process the contact data you provided during the order to personally inform you within the scope of our legal information obligations according to Art. 6 para. 1 lit. c GDPR. Your contact data will be used strictly for the purpose of notifications about updates owed by us and will only be processed by us to the extent necessary for the respective information.

To process your order, we also cooperate with the following service provider(s) who assist us wholly or partially in fulfilling concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.

8.2 Transfer of personal data to shipping service providers

- DHL

We use the following provider as a transport service provider: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany

We share your email address and/or phone number with the provider prior to delivery for the purpose of coordinating a delivery date or delivery notification in accordance with Art. 6 para. 1 lit. a GDPR, provided you have given your explicit consent during the ordering process. Otherwise, for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR, we only share the recipient's name and delivery address with the provider. The transfer only takes place to the extent necessary for the delivery of goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.

Consent can be revoked at any time with effect for the future towards the responsible party named above or towards the provider.

8.3 Use of payment service providers (payment services)

- Amazon Pay

One or more online payment methods from the following provider are available on this website: Amazon Payments Europe s.c.a., 38 avenue J.F. Kennedy, L-1855 Luxembourg

When selecting a payment method from the provider where you pay in advance (such as credit card payment), your payment data provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the content of your order will be shared with the provider in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data in this case is solely for the purpose of payment processing with the provider and only to the extent necessary for this purpose.
- Klarna

One or more online payment methods from the following provider are available on this website: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden

When selecting a payment method from the provider where you pay in advance (such as credit card payment), your payment data provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the content of your order will be shared with the provider in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data in this case is solely for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

When selecting a payment method where the provider pays in advance (such as invoice or installment purchase or direct debit), you will also be asked during the ordering process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, if applicable data for an alternative payment method).

To protect our legitimate interest in determining the creditworthiness of our customers, these data are forwarded by us to the provider for the purpose of a credit check in accordance with Art. 6 para. 1 lit. f GDPR. The provider checks, based on the personal data you have provided as well as other data (such as shopping cart, invoice amount, order history, payment experiences), whether the payment method you have selected can be granted with regard to payment and/or default risks.

In addition to internal provider criteria, identity and credit information from the following credit agencies may also be included in the decision within the scope of the application review in accordance with Art. 6 para. 1 lit. f GDPR:

https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies

The credit report may contain probability values (so-called score values). As far as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things but not exclusively, address data.

You can object to this processing of your data at any time by sending us a message or contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractually agreed payment processing.
- Paypal

One or more online payment methods from the following provider are available on this website: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

When selecting a payment method of the provider for which you advance payment, your payment data provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the content of your order are passed on to the provider in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data in this case is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

When selecting a payment method for which we advance payment, you will also be asked during the ordering process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, if applicable data on an alternative payment method).

In such cases, to protect our legitimate interest in determining your creditworthiness, these data are forwarded by us to the provider for the purpose of a credit check in accordance with Art. 6 para. 1 lit. f GDPR. The provider checks, based on the personal data you have provided as well as other data (such as shopping cart, invoice amount, order history, payment experiences), whether the payment method you have selected can be granted with regard to payment and/or default risks.

The credit report may contain probability values (so-called score values). As far as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things but not exclusively, address data.

You can object to this processing of your data at any time by sending us a message or contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractually agreed payment processing.

9) Web analytics services

Google (Universal) Analytics

This website uses Google (Universal) Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables an analysis of your use of our website.

By default, cookies are set by Google (Universal) Analytics when visiting the website. These are small text files stored on your device that collect certain information. This information includes your IP address, which is shortened by Google to exclude direct personal identification.

The information is transmitted to Google servers and further processed there. Transfers to Google LLC based in the USA are also possible.

Google uses the collected information on our behalf to evaluate your use of the website, compile reports on website activity for us, and provide other services related to website and internet usage. The IP address transmitted and shortened by your browser within Google Analytics is not merged with other data from Google. The data collected through the use of Google (Universal) Analytics is stored for two months and then deleted.

All processing described above, especially the setting of cookies on the device used, only takes place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR.
Without your consent, Google (Universal) Analytics will not be used during your visit to the site. You can revoke your consent at any time with effect for the future. To exercise your right of withdrawal, please deactivate this service via the "Cookie Consent Tool" provided on the website.

We have concluded a data processing agreement with Google that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

Further legal information about Google (Universal) Analytics can be found at https://business.safety.google/intl/de/privacy/, https://policies.google.com/privacy?hl=de&gl=de and at https://policies.google.com/technologies/partner-sites

Demographics
Google (Universal) Analytics uses the special "demographics" feature and can create statistics that provide information about the age, gender, and interests of site visitors. This is done by analyzing advertising and information from third parties. This allows target groups for marketing activities to be identified. However, the collected data cannot be assigned to any specific person and is deleted after being stored for a period of two months.

Google Signals
As an extension to Google (Universal) Analytics, Google Signals can be used on this website to create cross-device reports. If you have enabled personalized ads and linked your devices to your Google account, Google can, subject to your consent to the use of Google Analytics according to Art. 6 para. 1 lit. a GDPR, analyze your usage behavior across devices and create database models, including for cross-device conversions. We do not receive any personal data from Google, only statistics. If you want to stop cross-device analysis, you can disable the "Personalized Ads" feature in your Google account settings. Follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=de More information about Google Signals can be found at the following link: https://support.google.com/analytics/answer/7532985?hl=de

UserIDs
As an extension to Google (Universal) Analytics, the "UserIDs" feature can be used on this website. If you have consented to the use of Google (Universal) Analytics according to Art. 6 para. 1 lit. a GDPR, have set up an account on this website, and log in with this account on different devices, your activities, including conversions, can be analyzed across devices.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.

10) Retargeting/Remarketing and Conversion Tracking

10.1 Meta Pixel with enhanced data matching

Within our online offering, we use the "Meta Pixel" service from the following provider in enhanced data matching mode: Meta Platforms Ireland Limited, 4 Grand Canal Quare, Dublin 2, Ireland ("Meta")

When a user clicks on an ad we placed on Facebook or Instagram, the URL of our linked page is extended by a parameter using "Meta Pixel." This URL parameter is then entered into the user's browser after redirection by a cookie set by our linked page itself. Additionally, this cookie collects specific customer data such as the email address, which we collect on our website linked to the Facebook or Instagram ad during actions like purchases, account registrations, or sign-ups (enhanced data matching). The cookie is then read and enables the transmission of data, including specific customer data, to Meta.

We use "Meta Pixel" with enhanced data matching to make our advertisements (so-called "ads") on Facebook and/or Instagram more effective and to ensure they correspond to users' interests or have certain characteristics (e.g., interests in specific topics or products determined by the websites visited), which we transmit to Meta (so-called "Custom Audiences").

Furthermore, we analyze the effectiveness of our advertisements by tracking whether users were redirected to our website after clicking an ad (conversion). Compared to the standard version of "Meta Pixel," the enhanced data matching feature helps us better measure the effectiveness of our advertising campaigns by capturing more attributed conversions.

All transmitted data is stored and processed by Meta so that it can be assigned to the respective user profile, and Meta uses the data for its own advertising purposes according to Meta's data use policies (https://www.facebook.com/about/privacy/) can be used. The data may enable Meta and its partners to display ads on and off Facebook.

All the processing described above, especially setting cookies to read information on the device used, is only carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by disabling this service in the "Cookie Consent Tool" provided on the website.

We have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

The information generated by Meta is usually transmitted to a Meta server and stored there; in this context, it may also be transferred to servers of Meta Platforms Inc. in the USA.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

10.2 Google Ads Remarketing

This website uses retargeting technology from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

For this purpose, Google sets a cookie in the browser of your device, which automatically enables interest-based advertising using a pseudonymous cookie ID and based on the pages you visit. Further data processing only takes place if you have agreed to Google linking your internet and app browsing history with your Google account and using information from your Google account to personalize ads you view on the web. If you are logged into Google during your visit to our website, Google uses your data together with Google Analytics data to create and define audience lists for cross-device remarketing. For this, your personal data is temporarily linked with Google Analytics data by Google to form audiences. When using Google Ads remarketing, personal data may also be transferred to the servers of Google LLC in the USA.

All the processing described above, especially the setting of cookies to read information on the device used, is only carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, the use of retargeting technology during your visit to the site will not take place.

You can revoke your given consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

Details about the processing initiated by Google and how Google handles data from websites can be found here: https://policies.google.com/technologies/partner-sites

Further information about Google's privacy policies can be found here: https://business.safety.google/intl/de/privacy/ and https://www.google.de/policies/privacy/

11) Page functionalities

11.1 Facebook plugins

Plugins from the social network of the following provider are used on our website: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

These plugins enable direct interactions with content on the social network.

To enhance the protection of your data when visiting our website, the plugins are initially deactivated and integrated into the site using a so-called "2-click" or "Shariff" solution.

This integration ensures that when a page of our website containing such plugins is accessed, no connection to the provider's servers is established yet.

Only when you activate the plugins and thus give your consent to data transmission according to Art. 6 para. 1 lit. a GDPR does your browser establish a direct connection to the provider's servers. In this process, regardless of logging into an existing user profile, certain information about your device used (including your IP address), your browser, and your browsing history is transmitted to the provider and possibly further processed there.

If you are logged into an existing user profile on the provider's social network, information about interactions made via the plugins will also be published there and shown to your contacts.
You can revoke your consent at any time by deactivating the activated plugin by clicking it again. However, the revocation does not affect data that has already been transmitted to the provider.

Data may also be transferred to: Meta Platforms Inc., USA

We have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

11.2 Instagram plugins

Plugins from the social network of the following provider are used on our website: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

These plugins enable direct interactions with content on the social network.

To enhance the protection of your data when visiting our website, the plugins are initially deactivated and integrated into the site using a so-called "2-click" or "Shariff" solution.

This integration ensures that when a page of our website containing such plugins is accessed, no connection to the provider's servers is established yet.

Only when you activate the plugins and thus give your consent to data transmission according to Art. 6 para. 1 lit. a GDPR does your browser establish a direct connection to the provider's servers. In this process, regardless of logging into an existing user profile, certain information about your device used (including your IP address), your browser, and your browsing history is transmitted to the provider and possibly further processed there.

If you are logged into an existing user profile on the provider's social network, information about interactions made via the plugins will also be published there and shown to your contacts.
You can revoke your consent at any time by deactivating the activated plugin by clicking it again. However, the revocation does not affect data that has already been transmitted to the provider.

Data may also be transferred to: Meta Platforms Inc., USA

We have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.

11.3 Trusted Shops Trustbadge

Our website includes graphic elements from the following provider to display external customer reviews and/or an externally awarded quality seal: Trusted Shops AG, Subbelrather Str. 15C, 50823 Cologne, Germany

When you visit a page of our website that contains such graphic elements, your browser establishes a direct connection to the provider's servers to properly load the elements. Certain browser information, including your IP address, is transmitted to the provider in this process.

If personal data is also processed in this context, this is done in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in the optimal marketing of our offer and the appealing design of our website.

In the case of an online order with us, further processing may take place.

Depending on your explicit consent according to Art. 6 para. 1 lit. a GDPR, your order information (order total, order number, possibly purchased product) as well as your email address will be encrypted and transmitted to the provider via the Trustbadge after completing an order to check for an existing registration for the provider's services (especially "buyer protection") and, if necessary, to enable a new registration.

In the event of an existing registration or a new registration with the provider for their services (especially buyer protection), your order information (order total, order number, purchased product) as well as your email address will be transmitted to and further processed by the provider based on the contractual agreement with the provider in accordance with Art. 6 para. 1 lit. b GDPR to provide the services (especially buyer protection).

We are jointly responsible with the provider for the processing described above in accordance with Art. 26 GDPR. The contract on joint responsibility can be viewed here: https://help.etrusted.com/hc/de/articles/4402587369105-Contract-on-joint-responsibility-under-GDPR

11.4 Google Maps

This website uses an online map service from the following provider: Google Maps (API) by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”).

Google Maps is a web service for displaying interactive (land) maps to visually present geographic information. Using this service shows you our location and facilitates any possible directions.

As soon as you access the subpages where the Google Maps map is embedded, information about your use of our website (such as your IP address) is transmitted to Google servers and stored there; this may also involve transmission to the servers of Google LLC in the USA. This happens regardless of whether Google provides a user account through which you are logged in or whether a user account exists. If you are logged into Google, your data will be directly assigned to your account. If you do not want the assignment to your Google profile, you must log out before activating the button. Google stores your data (even for users not logged in) as usage profiles and evaluates them.

The collection, storage, and evaluation are carried out in accordance with Art. 6 para. 1 lit. f GDPR based on Google's legitimate interest in displaying personalized advertising, market research, and/or the demand-oriented design of Google websites. You have the right to object to the creation of these user profiles, but you must contact Google to exercise this right. If you do not agree to the future transmission of your data to Google as part of using Google Maps, you also have the option to completely disable the Google Maps web service by turning off JavaScript in your browser. Google Maps and thus the map display on this website can then no longer be used.

Where legally required, we have obtained your consent for the processing of your data as described above pursuant to Art. 6 para. 1 lit. a GDPR. You can revoke your given consent at any time with effect for the future. To exercise your revocation, please follow the objection procedure described above.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.

Further information on Google's privacy policies can be found here: https://business.safety.google/intl/de/privacy/

12) Tools and Miscellaneous

- DATEV

For the completion of accounting, we use the service of the cloud-based accounting software from the following provider: DATEV eG, Paumgartnerstr. 6-14, 90429 Nuremberg, Germany

The provider processes incoming and outgoing invoices as well as, if applicable, the bank transactions of our company to automatically capture invoices, match them to transactions, and from this create the financial accounting in a semi-automated process.

If personal data is also processed in this context, the processing is based on our legitimate interest in efficient organization and documentation of our business operations pursuant to Art. 6 para. 1 lit. f GDPR.

13) Data Subject Rights

13.1 The applicable data protection law grants you the following data subject rights (rights to information and intervention) against the controller regarding the processing of your personal data, whereby the respective legal basis for exercising these rights is referenced:

  • Right of access pursuant to Art. 15 GDPR;
  • Right to rectification pursuant to Art. 16 GDPR;
  • Right to erasure pursuant to Art. 17 GDPR;
  • Right to restriction of processing pursuant to Art. 18 GDPR;
  • Right to information pursuant to Art. 19 GDPR;
  • Right to data portability pursuant to Art. 20 GDPR;
  • Right to withdraw given consents pursuant to Art. 7 para. 3 GDPR;
  • Right to lodge a complaint pursuant to Art. 77 GDPR.

13.2 RIGHT TO OBJECT

IF WE PROCESS YOUR PERSONAL DATA BASED ON OUR OVERRIDING LEGITIMATE INTERESTS AFTER BALANCING INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, WITH EFFECT FOR THE FUTURE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA. HOWEVER, FURTHER PROCESSING IS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS, AND FREEDOMS, OR IF THE PROCESSING SERVES THE ASSERTION, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.

IF YOUR PERSONAL DATA IS PROCESSED BY US FOR DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING PURPOSES. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA FOR DIRECT MARKETING PURPOSES.

14) Duration of storage of personal data

The duration of storage of personal data is determined by the respective legal basis, the processing purpose, and—if applicable—additionally by the respective statutory retention period (e.g., commercial and tax law retention periods).

When processing personal data based on an explicit consent according to Art. 6 para. 1 lit. a GDPR, the affected data will be stored as long as you do not revoke your consent.

If there are statutory retention periods for data processed within the framework of contractual or contract-like obligations based on Art. 6 para. 1 lit. b GDPR, this data will be routinely deleted after the retention periods expire, provided it is no longer necessary for contract fulfillment or initiation and/or we no longer have a legitimate interest in further storage.

When processing personal data based on Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the assertion, exercise, or defense of legal claims.

When processing personal data for the purpose of direct advertising based on Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 para. 2 GDPR.

Unless otherwise specified in the other information of this declaration regarding specific processing situations, stored personal data will otherwise be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.