Privacy policy

1) Introduction and contact details of the controller

1.1 About is pleased that you visit our website and thanks you for your interest. Below we inform you about the handling of your personal data when using our website. Personal data means all data with which you can be personally identified.

1.2 The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is KG Thomas i Punkt Modelle Handelsgesellschaft mbH & Co., Hardenstraße 9, 20539 Hamburg, Germany, Tel.: 0407809880, Fax: 04078098829, E-Mail: shop@thomasipunkt.de. The person responsible for the processing of personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.

1.3 The controller has appointed a data protection officer, who can be reached as follows: "Andreas Freitag, Hardenstraße 9, 20539 Hamburg,
+49 (0) 40 780 988 0, datenschutz@thomasipunkt.de"

2) Data collection when visiting our website

2.1 When using our website for purely informational purposes, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the page server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time at the time of access
  • Amount of data sent in bytes
  • Source/referrer from which you accessed the site
  • Browser used
  • Operating system used
  • Used IP address (if applicable: in anonymized form)

The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. Data is not passed on or used otherwise. However, About reserves the right to review the server log files retrospectively if there are concrete indications of unlawful use.

2.2 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller). You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser's address bar.

3) Hosting & Content Delivery Network

3.1 Amazon Web Services

For hosting our website and displaying page content, we use the system of the following provider: Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA

All data collected on our website is processed on the provider's servers.
We have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties. 

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

3.2 Shopify

For hosting our website and displaying page content, we use the system of the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify")

Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada

All data collected on our website is processed on the provider's servers. We have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

When data is transferred to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

3.3 AWS-CloudFront

About use a Content Delivery Network from the following provider: Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA

This service allows us to deliver large media files such as graphics, page content, or scripts faster via a network of regionally distributed servers. The processing is carried out to protect our legitimate interest in improving the stability and functionality of our website according to Art. 6 para. 1 lit. f GDPR. We have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

3.4 Cloudflare

About use a Content Delivery Network from the following provider: Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA

This service allows us to deliver large media files such as graphics, page content, or scripts faster via a network of regionally distributed servers. The processing is carried out to protect our legitimate interest in improving the stability and functionality of our website according to Art. 6 para. 1 lit. f GDPR. We have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.

4) Cookies

To make visiting our website attractive and to enable the use of certain features, About use cookies, which are small text files stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called "session cookies"), while others remain on your device longer and allow the saving of page settings (so-called "persistent cookies"). In the latter case, you can find the storage duration in the overview of your web browser's cookie settings.

If personal data is processed through individual cookies we use, the processing is carried out according to Art. 6 para. 1 lit. b GDPR either for the performance of the contract, according to Art. 6 para. 1 lit. a GDPR in case of given consent, or according to Art. 6 para. 1 lit. f GDPR to protect our legitimate interests in the best possible functionality of the website as well as a customer-friendly and effective design of the site visit.

You can set your browser to inform you about the setting of cookies and decide individually whether to accept them or to exclude the acceptance of cookies for certain cases or in general.

Please note that if you do not accept cookies, the functionality of our website may be limited.

5) Contact

When contacting us (e.g., via contact form or email), personal data is processed exclusively for the purpose of handling and responding to your request and only to the extent necessary for this purpose.

The legal basis for processing this data is our legitimate interest in responding to your request according to Art. 6 para. 1 lit. f GDPR. If your contact concerns a contract, the additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted when it can be concluded from the circumstances that the matter in question has been conclusively resolved and no legal retention obligations apply.

6) Data processing when opening a customer account

According to Art. 6 para. 1 lit. b GDPR, personal data will continue to be collected and processed to the extent necessary if you provide it to us when opening a customer account. Which data is required for account opening can be found in the input mask of the corresponding form on our website.

You can delete your customer account at any time by sending a message to the above address of the responsible party. After deleting your customer account, your data will be deleted, provided that all contracts concluded through it have been fully settled, no legal retention periods apply, and we no longer have a legitimate interest in further storage.

7) Use of customer data for direct advertising

7.1 Subscription to our email newsletter

When you sign up for our email newsletter, we regularly send you information about our offers. The only mandatory information for sending the newsletter is your email address. Providing additional data is voluntary and is used to address you personally. We use the so-called double opt-in procedure for sending the newsletter, which ensures that you only receive newsletters after you have explicitly confirmed your consent to receive the newsletter by clicking a verification link sent to the specified email address.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 para. 1 lit. a GDPR. We store the IP address assigned by your Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any possible misuse of your email address at a later time. The data we collect when you sign up for the newsletter is used strictly for the intended purpose.

You can unsubscribe from the newsletter at any time via the designated link in the newsletter or by sending a corresponding message to the responsible party named above. After unsubscribing, your email address will be promptly deleted from our newsletter distribution list, unless you have explicitly consented to further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this statement.

7.2 Klaviyo

Our email newsletters are sent via this provider: Klaviyo, Inc., 125 Summer St., Ste 600, Boston, MA 02110, USA

Based on our legitimate interest in effective and user-friendly newsletter marketing, we forward the data you provide when signing up for the newsletter pursuant to Art. 6 para. 1 lit. f GDPR to this provider so that they can handle the newsletter distribution on our behalf.

Subject to your explicit consent pursuant to Art. 6 para. 1 lit. a GDPR, the provider also conducts a statistical success analysis of newsletter campaigns using web beacons or tracking pixels in the sent emails, which can measure open rates and specific interactions with the newsletter content. Device information (e.g., time of access, IP address, browser type, and operating system) is also collected and evaluated but is not merged with other data sets.

You can revoke your consent to newsletter tracking at any time with effect for the future.

About have concluded a data processing agreement with the provider that protects the data of our site visitors and prohibits sharing with third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

7.3 Product Availability Notification by Email

For temporarily unavailable items, you can sign up to receive email notifications about product availability. We will send you a one-time email notification about the availability of the item you selected. Mandatory information for sending this notification is your email address only. Providing additional data is voluntary and may be used to address you personally. For sending emails, we use the so-called double opt-in process, which ensures that you only receive a notification after you have explicitly confirmed your consent by clicking a verification link sent to the specified email address.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 para. 1 lit. a GDPR. We store the IP address assigned to you by your Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any possible misuse of your email address at a later time. The data collected by us when registering for our email notification service for product availability is used strictly for this purpose.

You can unsubscribe from availability notifications at any time by sending a corresponding message to the responsible party named above. After unsubscribing, your email address will be promptly removed from our designated distribution list, unless you have explicitly consented to further use of your data or we reserve the right to use your data beyond this in a legally permitted manner, about which we inform you in this statement.

7.4 Shopping Cart Reminders by Email

If you abandon your purchase with us before completing the order, you have the option to receive a one-time email reminder of the contents of your virtual shopping cart.

Mandatory information for sending this reminder is your email address only. Providing additional data is voluntary and may be used to address you personally. For sending emails, we use the so-called double opt-in process, which ensures that you only receive a notification after you have explicitly confirmed your consent by clicking a verification link sent to the specified email address.

By activating the confirmation link, you give us your consent to use your personal data according to Art. 6 para. 1 lit. a GDPR for sending a shopping cart reminder. In doing so, we store the IP address registered by your Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any possible misuse of your email address at a later time. The data collected by us when registering for our email notification service is used strictly for the intended purpose.

You can unsubscribe from the shopping cart reminders at any time by sending a corresponding message to the responsible party named at the beginning. After unsubscribing, your email address will be immediately deleted from our distribution list set up for this purpose, unless you have explicitly consented to further use of your data or we reserve the right to use your data beyond this in a legally permitted manner about which we inform you in this statement.

8) Data processing for order fulfillment

8.1 If required for contract processing for delivery and payment purposes, the personal data we collect will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 para. 1 lit. b GDPR.

If, based on a corresponding contract, we owe you updates for goods with digital elements or for digital products, we process the contact details you provided during the order to personally inform you within the scope of our legal information obligations according to Art. 6 para. 1 lit. c GDPR. Your contact details are used strictly for the purpose of notifications about updates we owe and are processed by us only to the extent necessary for the respective information.

To process your order, we also cooperate with the following service provider(s) who support us wholly or partly in fulfilling concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.

8.2 Transfer of personal data to shipping service providers

- DHL

As a transport service provider, About use the following provider: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany

About share your email address and/or phone number in accordance with Art. 6 para. 1 lit. a GDPR before delivery of the goods for the purpose of coordinating a delivery date or for delivery notification with the provider, provided you have given your explicit consent during the ordering process. Otherwise, for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR, only the recipient’s name and delivery address are shared with the provider. The disclosure only takes place to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.

Consent can be revoked at any time with effect for the future by contacting the responsible party named above or the provider.
- UPS

As a transport service provider, About use the following provider: United Parcel Service Deutschland Inc. & Co. OHG, Görlitzer Straße 1, 41460 Neuss, Germany

About share your email address and/or phone number in accordance with Art. 6 para. 1 lit. a GDPR before delivery of the goods for the purpose of coordinating a delivery date or for delivery notification with the provider, provided you have given your explicit consent during the ordering process. Otherwise, for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR, only the recipient’s name and delivery address are shared with the provider. The disclosure only takes place to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.

Consent can be revoked at any time with effect for the future by contacting the responsible party named above or the provider.

8.3 Use of payment service providers (payment services)

- Apple Pay

If you choose the payment method Apple Pay from Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, the payment processing is carried out via the Apple Pay function of your device running iOS, watchOS, or macOS by charging a payment card stored in Apple Pay. Apple Pay uses security features integrated into your device’s hardware and software to protect your transactions. To authorize a payment, you must enter a code you previously set and verify it using the Face ID or Touch ID function of your device.

For the purpose of payment processing, the information you provide during the ordering process, along with information about your order, is transmitted to Apple in encrypted form. Apple then encrypts this data again with a developer-specific key before the data is sent to the payment service provider of the payment card stored in Apple Pay to carry out the payment. The encryption ensures that only the website through which the purchase was made can access the payment data. After the payment has been made, Apple sends your device account number and a transaction-specific, dynamic security code to the originating website to confirm the payment success.

If personal data is processed during the described transmissions, the processing is carried out exclusively for the purpose of payment processing in accordance with Art. 6 para. 1 lit. b GDPR.

Apple stores anonymized transaction data, including the approximate purchase amount, the approximate date and time, and whether the transaction was successfully completed. Anonymization completely excludes any personal reference. Apple uses the anonymized data to improve Apple Pay and other Apple products and services.

If you use Apple Pay on the iPhone or Apple Watch to complete a purchase you made via Safari on the Mac, the Mac and the authorization device communicate over an encrypted channel on Apple servers. Apple does not process or store any of this information in a format that can identify you personally. You can disable the option to use Apple Pay on your Mac in your iPhone settings. Go to "Wallet & Apple Pay" and turn off "Allow Payments on Mac".

Further information on data protection with Apple Pay can be found at the following internet address: https://support.apple.com/de-de/HT203027
- Klarna

One or more online payment methods from the following provider are available on this website: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden

If you select a payment method from the provider where you pay in advance (such as credit card payment), your payment data provided during the order process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be shared with them in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data in this case is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

When selecting a payment method where the provider pays in advance (such as invoice or installment purchase or direct debit), you will also be asked during the order process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and if applicable, data on an alternative payment method).

To protect our legitimate interest in determining the creditworthiness of our customers, this data is forwarded by us to the provider for a credit check in accordance with Art. 6 para. 1 lit. f GDPR. The provider checks, based on the personal data you provided as well as other data (such as shopping cart, invoice amount, order history, payment experiences), whether the payment option you selected can be granted with regard to payment and/or default risks.

In addition to internal provider criteria according to Art. 6 para. 1 lit. f GDPR, identity and credit information from the following credit agencies may be included in the decision during the application review:

https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies

The credit report may contain probability values (so-called score values). As far as score values are included in the credit report result, they are based on a scientifically recognized mathematical-statistical method. The calculation of the score values includes, among other things but not exclusively, address data.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for proper payment processing under the contract.
- Paypal

One or more online payment methods from the following provider are available on this website: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

When selecting a payment method from the provider where you pay in advance, your payment data provided during the order process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order are passed on to them in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data in this case is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

If you select a payment method where we pay in advance, you will also be asked during the order process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and if applicable, data about an alternative payment method).

To protect our legitimate interest in determining your creditworthiness in such cases, these data are forwarded by us to the provider for the purpose of a credit check in accordance with Art. 6 para. 1 lit. f GDPR. The provider checks, based on the personal data you provide as well as other data (such as shopping cart, invoice amount, order history, payment experiences), whether the payment method you selected can be granted with regard to payment and/or default risks.

The credit report may contain probability values (so-called score values). As far as score values are included in the credit report result, they are based on a scientifically recognized mathematical-statistical method. The calculation of the score values includes, among other things but not exclusively, address data.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for proper payment processing under the contract.
- Shopify Payments

One or more online payment methods from the following provider are available on this website: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland

If you select a payment method from the provider where you pay in advance (such as credit card payment), your payment data provided during the order process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be shared with them in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data in this case is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.
- Instant bank transfer

One or more online payment methods from the following provider are available on this website: Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden

If you select a payment method from the provider where you pay in advance (such as credit card payment), your payment data provided during the order process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be shared with them in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data in this case is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

9) Online Marketing

AWIN Performance Advertising Network Affiliate

About participate in the affiliate program of the following provider: AWIN AG, Eichhornstraße 3, 10785 Berlin, Germany

In this context, About has placed links on our website that lead to offers on websites of the provider or third parties ("partner sites").

To measure the success of an affiliate link, evaluate orders generated through such a link, and handle the corresponding commission payments, the provider uses cookies and/or comparable technologies, which are generally set on the partner sites and for which we are not responsible under data protection law. In this context, the provider regularly processes the IP address and possibly other device information.

All processing described above, especially reading or storing information on the device you use, only takes place if you have given your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by using the cookie consent management options on the partner sites.

10) Web analytics services

10.1 Google Analytics 4

This website uses Google Analytics 4, a web analytics service from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables an analysis of your use of our website.

By default, Google Analytics 4 sets cookies when you visit the website, which are small text files stored on your device and collect certain information. This information also includes your IP address, which Google shortens by removing the last digits to exclude direct personal identification.

The information is transmitted to Google servers and further processed there. Transfers to Google LLC based in the USA are also possible.

Google uses the collected information on our behalf to evaluate your use of the website, compile reports on website activity for us, and provide other services related to website and internet usage. The IP address transmitted and shortened by your browser as part of Google Analytics is not merged with other data from Google. The data collected through the use of Google Analytics 4 is stored for a period of two months and then deleted.

All processing described above, especially the setting of cookies on the device used, only takes place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR.
Without your consent, the use of Google Analytics 4 during your site visit will not take place. You can revoke your given consent at any time with effect for the future. To exercise your right of withdrawal, please disable this service via the "Cookie Consent Tool" provided on the website.

About have concluded a data processing agreement with Google that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

Further legal information about Google Analytics 4 can be found at https://business.safety.google/intl/de/privacy/, https://policies.google.com/privacy?hl=de&gl=de and at https://policies.google.com/technologies/partner-sites

Demographics
Google Analytics 4 uses the special "demographics" feature and can create statistics that provide information about the age, gender, and interests of site visitors. This is done by analyzing advertising and third-party information. This allows audiences to be identified for marketing activities. However, the collected data cannot be assigned to any specific person and is deleted after being stored for two months.

Google Signals
As an extension to Google Analytics 4, this website can use Google Signals to create cross-device reports. If you have enabled personalized ads and linked your devices to your Google account, Google, subject to your consent to the use of Google Analytics under Art. 6 para. 1 lit. a GDPR, can analyze your usage behavior across devices and create database models, including for cross-device conversions. About receive no personal data from Google, only statistics. If you want to stop cross-device analysis, you can disable the "Personalized Ads" feature in your Google account settings. Follow the instructions on this page: https://support.google.com/My-Ad-Center-Help/answer/12155764?hl=de
More information about Google Signals can be found at the following link: https://support.google.com/analytics/answer/7532985?hl=de

UserIDs
As an extension to Google Analytics 4, the "UserIDs" feature can be used on this website. If you have consented to the use of Google Analytics 4 according to Art. 6 para. 1 lit. a GDPR, have set up an account on this website, and log in with this account on different devices, your activities, including conversions, can be analyzed across devices.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

10.2 etracker

On this website, data is collected and stored using technologies from etracker GmbH, Erste Brunnenstraße 1, 20459 Hamburg (www.etracker.com). From this data, pseudonymized usage profiles can be created and evaluated for the same purpose.

This website uses etracker exclusively without the use of cookies, which means that etracker never sets cookies on your device.

According to information from eTracker, only the website data from web servers and information that the web browser transmits to the web server to retrieve websites are used. This information is transmitted with each individual page request. However, no information is read from the user's device storage, nor is any information stored on this device.

If personal data is also processed in the described procedures, this is done on the basis of our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes according to Art. 6 para. 1 lit. f GDPR.

You can permanently object to the collection and storage of your visitor data for the future by using the opt-out function set up for this purpose on our website.

At the following internet address, you can find more information about etracker's privacy policy: https://www.etracker.com/de/datenschutz.html.

10.3 Google Tag Manager

This website uses the "Google Tag Manager," a service provided by the following provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: "Google").

Google Tag Manager provides a technical basis for bundling various web applications, including tracking and analytics services, and for calibrating, controlling, and linking them to conditions via a unified user interface. Google Tag Manager itself does not store or read any information on user devices. The service also does not perform independent data analyses. However, Google Tag Manager transmits your IP address to Google when the page is loaded and may store it there. Transmission to servers of Google LLC in the USA is also possible.

This processing is only carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, the use of Google Tag Manager during your site visit will not take place. You can revoke your given consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.

About have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.

Further legal information about Google Tag Manager can be found at https://business.safety.google/intl/de/privacy/ and https://policies.google.com/privacy?hl=de&gl=de

10.4 Hotjar

This website uses the web analytics service of the following provider: Hotjar Ltd, Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta

Using cookies and/or similar technologies (tracking pixels, web beacons, algorithms for reading device and browser information), the service collects and stores pseudonymized visitor data, including information about the device used such as the IP address and browser information, to analyze usage behavior on our website for statistical purposes and to create pseudonymized usage profiles. Among other things, this allows the evaluation of movement patterns (so-called heatmaps), which show the duration of page visits as well as interactions with page content (e.g., text entries, scrolling, clicks, and mouse-overs). The pseudonymization generally excludes direct personal identification. No merging with personal data collected by other means takes place.

All processing described above, especially reading or storing information on the device used, is only carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with future effect by disabling this service in the "Cookie Consent Tool" provided on the website.

About have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

10.5 Shopify Analytics

This website uses the web analytics service of the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland

Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada

Using cookies and/or similar technologies (tracking pixels, web beacons, algorithms for reading device and browser information), the service collects and stores pseudonymized visitor data, including information about the device used such as the IP address and browser information, to analyze usage behavior on our website for statistical purposes and to create pseudonymized usage profiles. Among other things, this allows the evaluation of movement patterns (so-called heatmaps), which show the duration of page visits as well as interactions with page content (e.g., text entries, scrolling, clicks, and mouse-overs). The pseudonymization generally excludes direct personal identification. No merging with personal data collected by other means takes place.

All processing described above, especially reading or storing information on the device used, is only carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with future effect by disabling this service in the "Cookie Consent Tool" provided on the website.

About have concluded a data processing agreement with the provider that protects the data of our site visitors and prohibits sharing with third parties.

When data is transferred to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

11) Retargeting/Remarketing and Conversion Tracking

11.1 Meta Pixel with advanced data matching

Within our online offering, we use the "Meta Pixel" service in advanced data matching mode from the following provider: Meta Platforms Ireland Limited, 4 Grand Canal Quare, Dublin 2, Ireland ("Meta").

When a user clicks on an advertisement we placed on Facebook or Instagram, the URL of our linked page is extended by a parameter using "Meta Pixel." This URL parameter is then recorded in the user's browser via a cookie set by our linked page itself after the redirection. Additionally, this cookie collects specific customer data such as the email address, which we gather on our website linked to the Facebook or Instagram ad during actions like purchases, account registrations, or sign-ups (advanced data matching). The cookie is then read and enables the transmission of data, including the specific customer data, to Meta.

About use "Meta Pixel" with advanced data matching to make our advertisements (so-called "ads") on Facebook and/or Instagram more effective and to ensure they match users' interests or have certain characteristics (e.g., interests in specific topics or products determined by the websites visited), which we transmit to Meta (so-called "Custom Audiences").

About also analyze the effectiveness of our advertisements by tracking whether users are redirected to our website after clicking on an ad (conversion). Compared to the standard version of "Meta Pixel," the advanced data matching feature helps us better measure the effectiveness of our advertising campaigns by capturing more attributed conversions.

All transmitted data is stored and processed by Meta so that assignment to the respective user profile is possible and Meta uses the data for its own advertising purposes according to Meta's data use policies (https://www.facebook.com/about/privacy/intl/de/privacy/) can be used. The data may enable Meta and its partners to display ads on and off Facebook.

All processing described above, especially setting cookies to read information on the device used, is only carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your given consent at any time with effect for the future by disabling this service in the "Cookie Consent Tool" provided on the website.

About have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

The information generated by Meta is usually transmitted to a Meta server and stored there; in this context, it may also be transferred to servers of Meta Platforms Inc. in the USA.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.

11.2 advanced store

This website uses retargeting technology from the following provider: advanced store GmbH, Stefan-Heym-Platz 1, 10367 Berlin, Germany

This enables us to specifically address visitors of our websites with personalized, interest-based advertising who have already shown interest in our shop and products. The display of advertising materials is based on a cookie-based analysis of past and current usage behavior.

In cases of retargeting technology, a cookie is stored on your computer or mobile device to collect pseudonymized data about your interests and thus tailor the advertising individually to the stored information. These cookies are small text files stored on your computer or mobile device. This way, you are shown advertising that is highly likely to match your product and information interests.

All the processing described above, especially setting cookies to read information on the device used, is only carried out if you have given us your explicit consent according to Art. 6 para. 1 lit. a GDPR. Without this consent, the use of retargeting technology during your visit to the site will not take place.

You can revoke your given consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.

11.3 This website uses retargeting technology from the following provider: targeting360 GmbH, Gredinger Str. 24a, 90453 Nuremberg

This technology allows visitors to our websites to be specifically addressed with personalized, interest-based advertising, targeting those who have already shown interest in our shop and products. The display of advertising media is based on a cookie-based analysis of past and current usage behavior, but no personal data is stored. In cases of retargeting technology, a cookie is stored on your computer or mobile device to collect pseudonymized data about your interests and thus tailor the advertising individually to the stored information. These cookies are small text files stored on your computer or mobile device. This way, you are shown advertising that is highly likely to match your product and information interests.

All the processing described above, especially setting cookies to read information on the device used, is only carried out if you have given us your explicit consent according to Art. 6 para. 1 lit. a GDPR. Without this consent, the use of retargeting technology during your visit to the site will not take place.

You can revoke your given consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.

12) Tools and Miscellaneous

12.1 - pathway solutions

For bookkeeping, we use the service of the cloud-based accounting software from the following provider: pathway solutions gmbh, c/o ba tax gmbh, Alstertwiete 3, 20099 Hamburg

The provider processes incoming and outgoing invoices as well as, if applicable, the company's bank transactions to automatically capture invoices, match them to transactions, and create the financial accounting in a semi-automated process.

If personal data is also processed in this context, the processing is based on our legitimate interest in efficient organization and documentation of our business operations according to Art. 6 para. 1 lit. f GDPR.

12.2 Cookie Consent Tool

This website uses a so-called "Cookie Consent Tool" to obtain effective user consents for cookies and cookie-based applications that require consent. The "Cookie Consent Tool" is displayed to users as an interactive interface when they visit the site, where consents for specific cookies and/or cookie-based applications can be granted by ticking checkboxes. By using this tool, all cookies/services that require consent are only loaded if the respective user has given the corresponding consent by ticking the checkboxes. This ensures that such cookies are only set on the user's device if consent has been given.

The tool sets technically necessary cookies to save your cookie preferences. Personal user data is generally not processed in this context.

If, in individual cases, personal data (such as the IP address) is processed for the purpose of storing, assigning, or logging cookie settings, this is done in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in a legally compliant, user-specific, and user-friendly consent management for cookies and thus in a legally compliant design of our website.

Another legal basis for the processing is also Art. 6 para. 1 lit. c GDPR. As controllers, we are legally obliged to make the use of technically unnecessary cookies dependent on the respective user consent.

If necessary, we have concluded a data processing agreement with the provider that ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.

Further information about the operator and the settings options of the cookie consent tool can be found directly in the corresponding user interface on our website.

13) Data subject rights

13.1 The applicable data protection law grants you the following data subject rights (rights to information and intervention) against the controller regarding the processing of your personal data, whereby the respective legal basis for exercising these rights is referred to:

  • Right of access pursuant to Art. 15 GDPR;
  • Right to rectification pursuant to Art. 16 GDPR;
  • Right to deletion pursuant to Art. 17 GDPR;
  • Right to restriction of processing pursuant to Art. 18 GDPR;
  • Right to information pursuant to Art. 19 GDPR;
  • Right to data portability pursuant to Art. 20 GDPR;
  • Right to withdraw given consents pursuant to Art. 7 para. 3 GDPR;
  • Right to lodge a complaint pursuant to Art. 77 GDPR.

13.2 OBJECTION RIGHT

IF About PROCESS YOUR PERSONAL DATA BASED ON OUR PREDOMINANT LEGITIMATE INTERESTS WITHIN THE SCOPE OF A BALANCE OF INTERESTS, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THIS PROCESSING FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, WITH EFFECT FOR THE FUTURE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE AFFECTED DATA. HOWEVER, FURTHER PROCESSING IS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS, AND FREEDOMS, OR IF THE PROCESSING SERVES THE ASSERTION, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.

IF YOUR PERSONAL DATA IS PROCESSED BY US TO CONDUCT DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING PURPOSES. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE AFFECTED DATA FOR DIRECT MARKETING PURPOSES.

14) Duration of storage of personal data

The duration of storage of personal data is determined by the respective legal basis, the processing purpose, and—if applicable—additionally by the respective statutory retention period (e.g., commercial and tax law retention periods).

When processing personal data based on explicit consent according to Art. 6 para. 1 lit. a GDPR, the affected data will be stored as long as you have not revoked your consent.

If there are statutory retention periods for data processed under contractual or contract-like obligations based on Art. 6 para. 1 lit. b GDPR, this data will be routinely deleted after the retention periods expire, provided it is no longer necessary for contract fulfillment or initiation and/or we no longer have a legitimate interest in further storage.

When processing personal data based on Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the assertion, exercise, or defense of legal claims.

When processing personal data for the purpose of direct marketing based on Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 para. 2 GDPR.

Unless otherwise specified by the other information in this declaration regarding specific processing situations, stored personal data will otherwise be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.