This privacy policy explains the nature, scope and purpose of the processing of personal data (hereinafter referred to simply as ‘data’) within our online service and the associated websites, functions and content, as well as external online presences, such as our social media profiles. (Hereinafter collectively referred to as the ‘online service’). With regard to the terms used, such as ‘processing’ or ‘controller’, we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Data Controller:
Gentle Art Of Music RPWL Lang & Wallner GbR
Dorfstraße 9
85356 Freising, Germany
VAT registration number: DE 814 065 318
Label code: LC-22956
Managing Directors/Owners: Kalle Wallner & Yogi Lang
Telephone: 0 8161 88 49 304
Fax: 0 8161 88 78 29
Email: info@gentleartofmusic.com
Types of data processed:
– Master data (e.g. names, addresses).
– Contact details (e.g. email addresses, telephone numbers).
– Content data (e.g. text entries, photographs, videos).
– Contract data (e.g. subject matter of the contract, term, customer category).
– Payment data (e.g. bank details, payment history).
– Usage data (e.g. websites visited, interest in content, access times).
– Meta/communication data (e.g. device information, IP addresses).
Processing of special categories of data (Art. 9(1) GDPR):
No special categories of data are processed.
Categories of data subjects:
– Customers, prospective customers, visitors and users of the online service, business partners.
– Visitors and users of the online service.
Hereinafter, we also refer to the data subjects collectively as “users”.
Purpose of processing:
– To provide the online service, its content and shop functions.
– To fulfil contractual obligations, provide services and offer customer care.
– To respond to enquiries and communicate with users.
– Marketing and advertising.
– Security measures.
As of: June 2024
This website uses Borlabs Cookie, which sets a technically necessary cookie (borlabs-cookie) to store your cookie consents.
The Borlabs cookie does not process any personal data. The ‘borlabs-cookie’ stores the consents you gave when you first accessed the website. If you wish to withdraw these consents, simply delete the cookie from your browser. When you access or reload the website, you will be asked for your cookie consent again.
1. Definitions
1.1. ‘Personal data’ means any information relating to an identified or identifiable natural person (hereinafter referred to as the ‘data subject’); a natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
1.2. ‘Processing’ means any operation or set of operations which is carried out on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data.
1.3. ‘Controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
2. Relevant legal bases
In accordance with Article 13 of the GDPR, we hereby inform you of the legal bases for our data processing activities. Where the legal basis is not specified in the privacy policy, the following applies: The legal basis for obtaining consent is Article 6(1)(a) and Article 7 of the GDPR; the legal basis for processing carried out to fulfil our services, implement contractual measures and respond to enquiries is Article 6(1)(b) of the GDPR; the legal basis for processing to fulfil our legal obligations is Article 6(1)(c) of the GDPR, and the legal basis for processing to safeguard our legitimate interests is Article 6(1)(f) of the GDPR. In the event that the vital interests of the data subject or another natural person necessitate the processing of personal data, Article 6(1)(d) of the GDPR serves as the legal basis.
3. Changes and updates to the privacy policy
We ask you to check the content of our privacy policy regularly. We will amend the privacy policy as soon as changes to the data processing activities we carry out make this necessary. We will inform you as soon as the changes require action on your part (e.g. consent) or any other individual notification.
4. Security measures
4.1. In accordance with Article 32 of the GDPR, and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk; These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access to, input of, disclosure of, and availability of the data, and ensuring its segregation. Furthermore, we have established procedures to ensure that data subjects’ rights are exercised, that data is erased and that we respond to any data breaches. Furthermore, we take the protection of personal data into account right from the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default (Article 25 of the GDPR).
4.2. The security measures include, in particular, the encrypted transmission of data between your browser and our server.
5. Disclosure and transfer of data
5.1. Where, in the course of our data processing activities, we disclose data to other individuals and organisations (data processors or third parties), transfer it to them or otherwise grant them access to the data, this is done only on the basis of a legal authorisation (e.g. where the transfer of data to third parties, such as payment service providers, is necessary for the performance of a contract in accordance with Article 6(1)(b) of the GDPR), you have given your consent, a legal obligation requires it, or on the basis of our legitimate interests (e.g. when engaging agents, hosting providers, tax, business and legal advisers, customer service, bookkeeping, billing and similar services that enable us to fulfil our contractual obligations, administrative tasks and duties efficiently and effectively).
5.2. Where we engage third parties to process data on the basis of a so-called ‘data processing agreement’, this is done in accordance with Article 28 of the GDPR.
6. Transfers to third countries
Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in connection with the use of third-party services or the disclosure or transfer of data to third parties, this will only take place if it is necessary to fulfil our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation or on the basis of our legitimate interests. Subject to statutory or contractual authorisations, we shall only process data in a third country, or have it processed there, if the specific conditions set out in Articles 44 et seq. of the GDPR are met. This means that processing takes place, for example, on the basis of specific safeguards, such as an officially recognised determination that a level of data protection equivalent to that of the EU exists (e.g. for the USA through the ‘Privacy Shield’) or compliance with officially recognised specific contractual obligations (so-called ‘standard contractual clauses’).
7. Rights of data subjects
7.1. You have the right to request confirmation as to whether your data is being processed, and to obtain access to this data, as well as further information and a copy of the data, in accordance with Article 15 of the GDPR.
7.2. In accordance with Article 16 of the GDPR, you have the right to request that data relating to you be completed or that any inaccurate data relating to you be rectified.
7.3. In accordance with Article 17 of the GDPR, you have the right to request that the relevant data be erased without delay or, alternatively, in accordance with Article 18 of the GDPR, to request a restriction on the processing of the data.
7.4. You have the right to request that the data concerning you, which you have provided to us, be made available to you in accordance with Article 20 of the GDPR and to request that it be transferred to other data controllers.
7.5. You also have the right, pursuant to Article 77 of the GDPR, to lodge a complaint with the competent supervisory authority.
8. Right to withdraw consent
You have the right to withdraw any consent you have given, in accordance with Article 7(3) of the GDPR, with effect for the future.
9. Right to object
You may object at any time to the future processing of your personal data in accordance with Article 21 of the GDPR. In particular, you may object to processing for the purposes of direct marketing.
10. Cookies and the right to object to direct marketing
10.1. ‘Cookies’ are small files that are stored on users’ computers. Various types of information may be stored within cookies. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after their visit to an online service. Temporary cookies, also known as ‘session cookies’ or ‘transient cookies’, are cookies that are deleted once a user leaves an online service and closes their browser. Such a cookie may, for example, store the contents of a shopping basket in an online shop or a login status. Cookies that remain stored even after the browser is closed are referred to as ‘permanent’ or ‘persistent’. For example, a user’s login status may be stored so that it is retained when they return to the site several days later. Similarly, such a cookie may store the user’s interests, which are used for audience measurement or marketing purposes. ‘Third-party cookies’ are cookies set by providers other than the controller operating the online service (whereas, if only the controller’s own cookies are used, these are referred to as ‘first-party cookies’).
10.2. We use temporary and permanent cookies and provide information about this in our privacy policy.
If users do not wish cookies to be stored on their computer, they are asked to disable the relevant option in their browser’s settings. Stored cookies can be deleted via the browser’s settings. Disabling cookies may result in functional limitations on this website.
10.3. A general objection to the use of cookies for online marketing purposes can be raised for a wide range of services, particularly in the case of tracking, via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, the storage of cookies can be prevented by disabling them in your browser settings. Please note that, in such cases, you may not be able to use all the features of this website.
11. Erasure of data
11.1. The data we process will be deleted or its processing restricted in accordance with Articles 17 and 18 of the GDPR. Unless expressly stated otherwise in this privacy policy, the data stored by us will be deleted as soon as it is no longer required for its intended purpose and there are no statutory retention obligations preventing its deletion. Where data is not erased because it is required for other, legally permissible purposes, its processing will be restricted. This means that the data will be blocked and not processed for any other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
11.2. Germany: In accordance with statutory requirements, records must be retained for a period of 6 years in particular, pursuant to Section 257(1) of the German Commercial Code (HGB) (commercial ledgers, inventories, opening balance sheets, annual accounts, commercial correspondence, accounting vouchers, etc.) and for 10 years in accordance with Section 147(1) of the German Fiscal Code (AO) (ledgers, records, management reports, accounting vouchers, commercial and business correspondence, documents relevant to taxation, etc.
11.3. Austria: In accordance with statutory requirements, documents are retained for 7 years in particular pursuant to Section 132(1) of the Austrian Federal Tax Code (BAO) (accounting records, supporting documents/invoices, accounts, vouchers, business documents, statements of income and expenditure, etc.), for 22 years in relation to immovable property, and for 10 years in the case of documents relating to services supplied electronically, telecommunications, radio and television services supplied to non-business customers in EU Member States for which the Mini One-Stop Shop (MOSS) is used.
12. Order processing in the online shop and customer account
12.1. We process our customers’ data as part of the ordering process in our online shop to enable them to select and order the chosen products and services, as well as to facilitate payment, delivery and fulfilment.
12.2. The data processed includes master data, communication data, contractual data and payment data; the data subjects are our customers, prospective customers and other business partners. The processing is carried out for the purpose of providing contractual services in connection with the operation of an online shop, billing, delivery and customer services. In doing so, we use session cookies to store the contents of the shopping basket and persistent cookies to store the login status.
12.3. Processing is carried out on the basis of Article 6(1)(b) (execution of orders) and (c) (legally required archiving) of the GDPR. The information marked as required is necessary for the conclusion and performance of the contract. We disclose the data to third parties only in connection with delivery, payment or in accordance with statutory permissions and obligations towards legal advisers and public authorities. The data is processed in third countries only where this is necessary for the performance of the contract (e.g. at the customer’s request in connection with delivery or payment).
12.4. Users may optionally create a user account, which allows them, in particular, to view their orders. During registration, users are informed of the mandatory details required. User accounts are not public and cannot be indexed by search engines. Once users have closed their user account, their data relating to that account will be deleted, subject to any retention required for commercial or tax law purposes in accordance with Article 6(1)(c) of the GDPR. Information in the customer account remains there until it is deleted, after which it is archived in the event of a legal obligation. It is the users’ responsibility to back up their data prior to the end of the contract following cancellation.
12.5. As part of the registration process, subsequent logins and the use of our online services, we store the IP address and the time of the respective user action. This data is stored on the basis of our legitimate interests, as well as the users’ interests in protection against misuse and other unauthorised use. This data is not, as a matter of principle, disclosed to third parties, unless it is necessary to pursue our claims or there is a legal obligation to do so in accordance with Article 6(1)(c) of the GDPR.
12.6. Data is deleted once statutory warranty obligations and comparable obligations have expired; the necessity of retaining the data is reviewed every three years; in the case of statutory archiving obligations, the data will be deleted upon their expiry (end of the commercial law (6 years) and tax law (10 years) retention periods); details in the customer account remain until the account is deleted.
13. Business analyses and market research
13.1. In order to run our business efficiently and to identify market trends and the wishes of customers and users, we analyse the data available to us relating to business transactions, contracts, enquiries, etc. In doing so, we process inventory data, communication data, contract data, payment data, usage data and metadata on the basis of Article 6(1)(f) of the GDPR, whereby the data subjects include customers, prospective customers, business partners, visitors and users of the online service. The analyses are carried out for the purposes of business management evaluations, marketing and market research. In doing so, we may take into account the profiles of registered users, including details such as their purchase history. The analyses help us to improve user-friendliness, optimise our services and enhance operational efficiency. The analyses are used solely by us and are not disclosed externally, unless they consist of anonymous analyses based on aggregated data.
13.2. Where such analyses or profiles are personal data, they shall be deleted or anonymised upon termination of the user’s account; otherwise, they shall be deleted or anonymised two years after the conclusion of the contract. Furthermore, overall business analyses and general trend assessments shall be compiled anonymously wherever possible.
2. A customer’s creditworthiness may be checked if there is otherwise a risk of non-payment, i.e. if the goods are delivered without payment having been received (i.e. if the customer chooses to purchase on account). However, there is no risk of non-payment if, for example, the customer chooses the prepayment option or makes payment via a third-party provider such as PayPal.
It should also be noted that obtaining an automated credit reference constitutes an ‘automated individual decision’ within the meaning of Article 22 of the GDPR, i.e. a legal decision made without human intervention. This is permissible if the customer has given their consent or if the decision is necessary for the conclusion of the contract. Whether the decision is necessary has not yet been conclusively clarified, but is widely regarded as the case, including by the author of this template. However, if you wish to rule out any risk, you should obtain consent.
Consent is also required if the credit check is already being used to decide whether the ‘on account’ option should be displayed in the first place. This is because the customer might have opted for prepayment or PayPal anyway, in which case the credit check would not have been necessary.
Such consent could, for example, read as follows:
I consent to a credit check being carried out in order to determine, via an automated process (Article 22 of the GDPR), whether the option to purchase on account will be offered. Further information on the credit check, the credit reference agencies used, the procedure and your rights to object can be found in our Privacy Policy.
14. Credit Reference
14.1. Where we make an advance payment (e.g. for purchases on account), we reserve the right, in order to safeguard our legitimate interests, to obtain an identity and credit reference from specialist service providers (credit reference agencies) for the purpose of assessing credit risk on the basis of mathematical and statistical methods.
14.2. As part of the credit check, we will transmit the following personal data relating to the customer (name, postal address, date of birth, details of the type of contract, bank details [please specify further details if applicable]) to the following credit reference agencies:
SCHUFA-Gesellschaft (SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden), privacy policy: https://www.schufa.de/de/ueber-uns/daten-scoring/.
14.3. We process the information received from credit reference agencies regarding the statistical probability of default as part of a reasonable discretionary decision on the establishment, performance and termination of the contractual relationship. We reserve the right to refuse payment on account or any other advance payment in the event of a negative credit check result.
14.4. The decision as to whether we provide advance performance is made, in accordance with Article 22 of the GDPR, solely on the basis of an automated decision in each individual case, which our software carries out on the basis of the information provided by the credit reference agency.
14.5 Where we obtain your express consent, the legal basis for the credit check and the transfer of the customer’s data to credit reference agencies is consent in accordance with Article 6(1)(a) and Article 7 of the GDPR. If no consent is obtained, our legitimate interests in safeguarding our payment claims form the legal basis in accordance with Article 6(1)(f) of the GDPR.
15. Contact and Customer Service
15.1. When you contact us (via the contact form or by email), your details are processed for the purpose of handling your enquiry and its resolution in accordance with Article 6(1)(b) of the GDPR.
15.2. Your details may be stored in our Customer Relationship Management system (‘CRM system’) or a similar enquiry management system.
15.3. We delete enquiries once they are no longer required. We review the necessity of retaining them every two years; we store enquiries from customers who have a customer account permanently and refer to the information in the customer account regarding deletion. Furthermore, the statutory archiving obligations apply.
16. Collection of access data and log files
16.1. On the basis of our legitimate interests within the meaning of Article 6(1)(f) of the GDPR, we collect data on every access to the server on which this service is hosted (so-called server log files). Access data includes the name of the webpage accessed, the file, the date and time of access, the volume of data transferred, confirmation of successful access, browser type and version, the user’s operating system, the referrer URL (the previously visited page), the IP address and the requesting provider.
16.2. Log file information is stored for a maximum of seven days for security reasons (e.g. to investigate cases of misuse or fraud) and is subsequently deleted. Data which must be retained for further evidence purposes is exempt from deletion until the relevant incident has been fully clarified.
17. Online Presence on Social Media
17.1. On the basis of our legitimate interests within the meaning of Article 6(1)(f) of the GDPR, we maintain an online presence on social networks and platforms in order to communicate with customers, prospective customers and users active on these platforms and to inform them about our services. When accessing the respective networks and platforms, the terms and conditions and data processing policies of their respective operators apply.
17.2 Unless otherwise stated in our privacy policy, we process users’ data where they communicate with us within social networks and platforms, e.g. by posting on our online presences or sending us messages.
If the ‘Remarketing’ or ‘Google Analytics Audiences’ functions are used, the following passage regarding these functions must also be included as a second point:
17.2. We use Google Analytics to ensure that adverts placed within Google’s advertising services and those of its partners are shown only to users who have demonstrated an interest in our online offering or who exhibit certain characteristics (e.g. interests in specific topics or products, determined on the basis of the websites visited), which we transmit to Google (so-called ‘remarketing’ or ‘Google Analytics Audiences’). We also use Remarketing Audiences to ensure that our adverts match users’ potential interests and do not come across as intrusive.
18. Google Analytics
18.1. On the basis of our legitimate interests (i.e. an interest in the analysis, optimisation and commercial operation of our online service within the meaning of Article 6(1)(f) of the GDPR), we use Google Analytics, a web analytics service provided by Google LLC (‘Google’). Google uses cookies. The information generated by the cookie regarding users’ use of the online service is usually transmitted to a Google server in the USA and stored there.
18.2. Google is certified under the Privacy Shield Agreement and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
18.3. Google will use this information on our behalf to analyse how users use our website, to compile reports on activity within the website, and to provide us with other services relating to the use of the website and internet usage. In doing so, pseudonymous user profiles may be created from the processed data.
18.4. We only use Google Analytics with IP anonymisation enabled. This means that users’ IP addresses are truncated by Google within Member States of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there.
18.5. The IP address transmitted by the user’s browser is not combined with any other data held by Google. Users can prevent the storage of cookies by adjusting the settings in their browser software; users can also prevent Google from collecting the data generated by the cookie and relating to their use of the online service, as well as prevent Google from processing this data, by downloading and installing the browser plug-in available via the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
18.6. For further information on Google’s use of data, as well as options for adjusting settings and opting out, please visit Google’s websites: https://www.google.com/intl/de/policies/privacy/partners (“How Google uses data when you use our partners’ websites or apps”), https://policies.google.com/technologies/ads (“Use of data for advertising purposes”), https://adssettings.google.com/authenticated (“Manage the information Google uses to show you adverts”).
19. Google Re/Marketing Services
19.1. On the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and commercial operation of our online offering within the meaning of Article 6(1)(f) of the GDPR), we use the marketing and remarketing services (hereinafter “Google Marketing Services”) provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, (‘Google’).
19.2. Google is certified under the Privacy Shield Agreement and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
19.3. Google’s marketing services enable us to display adverts for and on our website in a more targeted manner, so as to present users only with adverts that are likely to match their interests. If, for example, a user is shown adverts for products they have shown an interest in on other websites, this is referred to as ‘remarketing’. For these purposes, when our website or other websites on which Google Marketing Services are active are accessed, a Google code is executed directly by Google and so-called (re)marketing tags (invisible graphics or code, also known as ‘web beacons’) are embedded in the website. With the help of these, an individual cookie – i.e. a small file – is stored on the user’s device (comparable technologies may also be used instead of cookies). The cookies may be set by various domains, including google.com, doubleclick.net, invitemedia.com, admeld.com, googlesyndication.com or googleadservices.com. This file records which websites the user has visited, what content they are interested in and which offers they have clicked on, as well as technical information about the browser and operating system, referring websites,Visiting times and further details regarding the use of the online service. Users’ IP addresses are also recorded; in this regard, we would like to point out, in the context of Google Analytics, that IP addresses are truncated within Member States of the European Union or in other signatory states to the Agreement on the European Economic Area, and are only transmitted in full to a Google server in the USA – where they are then truncated – in exceptional cases. The IP address is not combined with the user’s data held within other Google services. Google may also combine the information mentioned above with information from other sources. If the user subsequently visits other websites, they may be shown adverts tailored to their interests.
19.4. User data is processed pseudonymously as part of Google Marketing Services. This means that Google does not, for example, store or process users’ names or email addresses, but instead processes the relevant data on a cookie-by-cookie basis within pseudonymous user profiles. In other words, from Google’s perspective, ads are not managed and displayed for a specifically identified individual, but rather for the cookie holder, regardless of who that cookie holder is. This does not apply if a user has expressly permitted Google to process the data without this pseudonymization. The information collected by Google Marketing Services about users is transmitted to Google and stored on Google’s servers in the United States.
19.5. The Google marketing services we use include, among others, the online advertising program “Google AdWords.” In the case of Google AdWords, each AdWords customer receives a different “conversion cookie.” Cookies cannot therefore be tracked across the websites of AdWords customers. The information collected via the cookie is used to generate conversion statistics for AdWords customers who have opted for conversion tracking. AdWords customers are informed of the total number of users who clicked on their ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users.
19.6. We may display third-party advertisements using Google’s “DoubleClick” marketing service. DoubleClick uses cookies that enable Google and its partner websites to serve ads based on users’ visits to this website or other websites on the Internet.
19.7. We may integrate third-party advertisements based on the Google marketing service “AdSense.” AdSense uses cookies that enable Google and its partner websites to display ads based on users’ visits to this website or other websites on the Internet.
19.8. We may also use the “Google Optimizer” service. Google Optimizer allows us, as part of so-called “A/B testing,” to track the effects of various changes to a website (e.g., changes to input fields, design, etc.). Cookies are stored on users’ devices for these testing purposes. Only pseudonymous user data is processed in this process.
19.9. We may also use “Google Tag Manager” to integrate and manage Google’s analytics and marketing services on our website.
19.10. For more information on Google’s use of data for marketing purposes, please visit the overview page: https://policies.google.com/technologies/ ads; Google’s Privacy Policy is available at https://policies.google.com/privacy.
19.11. If you wish to opt out of interest-based advertising through Google Marketing Services, you can use the settings and opt-out options provided by Google: https://adssettings.google.com/authenticated.
Furthermore, when using the Facebook Pixel, we utilize the additional “extended matching” feature (which involves transmitting data such as users’ phone numbers, email addresses, or Facebook IDs to Facebook in encrypted form) to create target audiences (“Custom Audiences” or “Lookalike Audiences”). Further information on “Advanced Matching”: https://www.facebook.com/business/help/611774685654668).
We also use the “Custom Audiences from File” feature provided by the social network Facebook, Inc. In this case, the email addresses of newsletter recipients are uploaded to Facebook. The upload process is encrypted. The upload is used solely to identify recipients of our Facebook ads. Our goal is to ensure that the ads are shown only to users who are interested in our information and services.
Note on Opt-Out: Please note that, as of the time this template was created, Facebook does not offer an opt-out option, so you must implement it yourself. If you do not, you must remove this section. This can be implemented, for example, using JavaScript (to set the opt-out link) and, when the page loads, via PHP (which checks whether the opt-out cookie has been set and only loads the Facebook pixel if the result is negative). When a user visits the website, the system must check whether the “opt-out” cookie has been set. If so, the “Facebook pixel” must not be loaded.
If you implement your own opt-out, please include the following addition:
To prevent your data from being collected via the Facebook Pixel on our website, please click the following link: Facebook Opt-Out Note: When you click the link, an “opt-out” cookie will be stored on your device. If you delete the cookies in this browser, you will need to click the link again. Furthermore, the opt-out applies only within the browser you are using and only within our web domain where the link was clicked.
20. Facebook, Custom Audiences, and Facebook Marketing Services
20.1. Within our online service, based on our legitimate interests in analyzing, optimizing, and operating our online service in an economically viable manner, and for these purposes, we use the so-called “Facebook Pixel” from the social network Facebook, which is operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA, or, if you are located in the EU, by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”).
20.2. Facebook is certified under the Privacy Shield Framework and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active).
20.3. With the help of the Facebook Pixel, Facebook is able, on the one hand, to identify visitors to our online platform as a target audience for displaying ads (so-called “Facebook Ads”). Accordingly, we use the Facebook Pixel to display the Facebook Ads we place only to those Facebook users who have shown an interest in our online offering or who exhibit certain characteristics (e.g., interests in specific topics or products, determined based on the websites they have visited), which we transmit to Facebook (so-called “Custom Audiences”). We also use the Facebook Pixel to ensure that our Facebook ads align with users’ potential interests and do not come across as intrusive. Furthermore, the Facebook Pixel allows us to track the effectiveness of Facebook ads for statistical and market research purposes by determining whether users were redirected to our website after clicking on a Facebook ad (so-called “conversion”).
20.4. Facebook processes the data in accordance with its Data Use Policy. General information regarding the display of Facebook ads can be found in Facebook’s Data Use Policy: https://www.facebook.com/policy.php. Specific information and details about the Facebook Pixel and how it works can be found in Facebook’s Help Center: https://www.facebook.com/business/help/651294705016616.
20.5. You can object to the collection of data by the Facebook Pixel and the use of your data for the display of Facebook ads. To control the types of ads displayed to you on Facebook, you can visit the page set up by Facebook and follow the instructions there regarding usage-based advertising settings: https://www.facebook.com/settings?tab=ads. These settings apply across all platforms, meaning they are applied to all devices, such as desktop computers or mobile devices.
20.6. You can also opt out of cookies used for audience measurement and advertising purposes via the Network Advertising Initiative’s opt-out page (http://optout.networkadvertising.org/), as well as the U.S. website (http://www.aboutads.info/choices) or the European website (http://www.youronlinechoices.com/uk/ your-ad-choices/).
21. Facebook Social Plugins
21.1. Based on our legitimate interests (i.e., our interest in the analysis, optimization, and economic operation of our online offering within the meaning of Article 6(1)(f) of the GDPR), we use social plugins (“plugins”) from the social network facebook.com, which is operated by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”). The plugins may display interactive elements or content (e.g., videos, graphics, or text posts) and can be recognized by one of the Facebook logos (a white “f” on a blue tile, the terms “Like,” “Gefällt mir,” or a “thumbs-up” icon) or are labeled with the phrase “Facebook Social Plugin.” The list and appearance of the Facebook Social Plugins can be viewed here: https://developers.facebook.com/docs/plugins/.
21.2. Facebook is certified under the Privacy Shield Framework and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active).
21.3. When a user accesses a feature of this online service that contains such a plugin, their device establishes a direct connection to Facebook’s servers. The content of the plugin is transmitted directly from Facebook to the user’s device and integrated into the online service. In the process, user profiles may be created based on the processed data. We therefore have no influence over the scope of the data that Facebook collects using this plugin and are informing users accordingly based on the information available to us.
21.4. By integrating the plugins, Facebook receives the information that a user has accessed the corresponding page of the online service. If the user is logged into Facebook, Facebook can associate the visit with the user’s Facebook account. When users interact with the plugins—for example, by clicking the “Like” button or posting a comment—the corresponding information is transmitted directly from their device to Facebook and stored there. Even if a user is not a Facebook member, there is still a possibility that Facebook may obtain and store their IP address. According to Facebook, only an anonymized IP address is stored in Germany.
May 21. Users can find information on the purpose and scope of data collection, as well as the further processing and use of data by Facebook, and the related rights and settings options for protecting users’ privacy, in Facebook’s Privacy Policy: https://www.facebook.com/about/privacy/.
21.6. If a user is a Facebook member and does not want Facebook to collect data about them via this online service and link it to their membership data stored on Facebook, they must log out of Facebook and delete their cookies before using our online service. Additional settings and the ability to opt out of the use of data for advertising purposes are available within the Facebook profile settings: https://www.facebook.com/settings?tab=ads or via the U.S. site http://www.aboutads.info/choices/ or the EU site http://www.youronlinechoices.com/. These settings apply across all platforms, meaning they are applied to all devices, such as desktop computers or mobile devices.
22. Communication via Mail, Email, Fax, or Telephone
22.1 We use means of remote communication, such as mail, telephone, or email, for business transactions and marketing purposes. In doing so, we process customer records, address and contact information, and contract data of customers, participants, prospective customers, and communication partners.
22.2 Processing is based on Article 6(1)(a), Article 7 of the GDPR, and Article 6(1)(f) of the GDPR in conjunction with legal requirements for promotional communications. Contact is made only with the consent of the contact persons or within the scope of legal permissions, and the processed data is deleted as soon as it is no longer necessary, or otherwise upon objection, revocation, or the cessation of the legal basis for processing, or in accordance with statutory archiving obligations.
23. Integration of Third-Party Services and Content
23.1. Within our online offering, we rely on our legitimate interests (i.e., our interest in the analysis, optimization, and economic operation of our online offering within the meaning of Art. 6(1)(f) of the GDPR) to integrate content or services from third-party providers in order to incorporate their content and services, such as videos or fonts (hereinafter collectively referred to as “Content”). This always requires that the third-party providers of this content collect the users’ IP addresses, as they would not be able to send the content to the users’ browsers without the IP address. The IP address is therefore necessary for the display of this content. We make every effort to use only such content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. These “pixel tags” allow information—such as visitor traffic on the pages of this website—to be analyzed. This pseudonymous information may also be stored in cookies on the user’s device and may include, among other things, technical information about the browser and operating system, referring websites, time of visit, and other details regarding the use of our online service, as well as be linked to such information from other sources.
23.2. The following list provides an overview of third-party providers and their content, along with links to their privacy policies, which contain further information on data processing and—in some cases, as already mentioned here—options to object (so-called “opt-out”)
– If our customers use third-party payment services (e.g., PayPal or Sofortüberweisung), the terms and conditions and privacy policies of the respective third-party providers apply, which are available on their respective websites or within the transaction applications.
– Maps provided by the “Google Maps” service from the third-party provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://www.google.com/settings/ads/.
– Videos from the “YouTube” platform provided by the third-party provider Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://www.google.com/settings/ads/.
– Our website incorporates features from the Google+ service. These features are provided by the third-party provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. If you are logged into your Google+ account, you can link the content of our pages to your Google+ profile by clicking the Google+ button. This allows Google to associate your visit to our pages with your user account. Please note that, as the provider of these pages, we have no knowledge of the content of the data transmitted or how it is used by Google+. Privacy Policy: https://policies.google.com/privacy, Opt-Out: https://adssettings.google.com/authenticated.
– Features of the Instagram service are integrated into our website. These features are provided by Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA. If you are logged into your Instagram account, you can link the content on our pages to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to our pages with your user account. Please note that, as the provider of these pages, we have no knowledge of the content of the data transmitted or how Instagram uses it. Privacy Policy: http://instagram.com/about/legal/privacy/.
– We use social plugins from the social network Pinterest, which is operated by Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA (“Pinterest”). When you visit a page that contains such a plugin, your browser establishes a direct connection to Pinterest’s servers. The plugin transmits log data to Pinterest’s servers in the United States. This log data may include your IP address, the addresses of the websites you have visited that also contain Pinterest features, your browser type and settings, the date and time of the request, how you use Pinterest, and cookies. Privacy Policy: https://about.pinterest.com/de/privacy-policy.
– Our online service may incorporate features of the Twitter service or platform (hereinafter referred to as “Twitter”). Twitter is a service provided by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. These features include displaying our tweets on Twitter within our online service, linking to our Twitter profile, and providing the ability to interact with tweets and Twitter features, as well as measuring whether users access our online service via the advertisements we place on Twitter (so-called conversion tracking). Twitter is certified under the Privacy Shield Framework and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000TORzAAO&status=Active). Privacy Policy: https://twitter.com/de/privacy, Opt-out: https://twitter.com/personalization.
You are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from YouTube. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More Information