HUUS

Privacy Policy (GDPR compliant)

Privacy Policy

1. Information on the collection of personal data and contact details of the controller
2. Data collection when visiting our website
3. Cookies
4. Data processing for order handling
5. Data processing when opening a customer account and for contract processing
6. Contact
7. Use of single sign-on procedures
8. Use of your data for direct advertising
9. Use of social media: social plugins
10. Use of social media: video
11. Online marketing
12. Web analytics services
13. Retargeting / Remarketing / Referral advertising
14. Use of a live chat system
15. Tools and miscellaneous
16. Rights of the data subject
17. Storage period of personal data

1. Information on the collection of personal data and contact details of the controller

1.1. Thank you for visiting our website. Below we would like to inform you about how we handle your personal data when you use our website. Personal data generally means all data with which you can be personally identified.

1.2. The controller responsible for data processing on our website within the meaning of the General Data Protection Regulation (GDPR) is:

Huus GmbH
Pfnorstraße 10
64293 Darmstadt
Germany
Tel.:+49 6151 7076968
Email: hello@huus.io

1.3. To protect the security of your data during transmission, we use encryption procedures in line with the current state of the art (e.g. SSL or TSL) via HTTPS.

2. Data collection when visiting our website

Each time our website is accessed, our system automatically collects data and information that your browser transmits to our server (so-called "server log files"). The following data, which is technically necessary for us, is collected:

The legal basis for processing is Art. 6 (1) lit. f GDPR due to our legitimate interest in improving the stability and maintaining the functionality of our website. The data is not passed on or otherwise used. Temporary storage of the IP address by the system is necessary in order to deliver the website to the user's computer. For this purpose, the user's IP address must remain stored for the duration of the session.
We reserve the right to review the server log files retrospectively if there are concrete indications of unlawful use. The data is deleted as soon as it is no longer required for the purpose for which it was collected. In the case of data collection for providing the website, this is the case when the respective session has ended.
If the data is stored in log files, this is the case after no later than seven days. Storage beyond this is possible. In this case, the users' IP addresses are deleted or altered so that it is no longer possible to identify the accessing client. The collection of data for providing the website and the storage of data in log files is absolutely necessary for the operation of the website. Consequently, the user has no right to object.

3. Cookies

Our website uses cookies.

Cookies are text files that are stored on the user's device. When a user accesses a website, a cookie can be stored on the user's operating system. Some functions of our website cannot be offered without the use of cookies. For this purpose, it is necessary that the browser is recognized again after changing pages. The user data collected by technically necessary cookies is not used to create user profiles. The purposes stated above also constitute our legitimate interest in the processing of personal data pursuant to Art. 6 (1) lit. f) GDPR.

In addition, our website uses cookies that enable analysis of users' surfing behavior (so-called third-party cookies). More detailed information on scope, purpose, legal basis, and objection options can be found in the respective sections of the relevant chapter of this privacy policy.

As a user, you have full control over the use of cookies. By changing the settings in your internet browser, you can disable, restrict, or delete the transmission of cookies. If you disable cookies for our website, it may no longer be possible to use all functions of the website in full. You can prevent the transmission of Flash cookies by changing the Flash Player settings.

You can find help on the settings in the respective help menu of your browser under the following links:
Internet Explorer: http://windows.microsoft.com/de-DE/windows-vista/Block-or-allow-cookies
Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
Chrome: http://support.google.com/chrome/bin/answer.py?hl=de&hlrm=en&answer=95647
Safari: https://support.apple.com/de-de/guide/safari/sfri11471/mac
Opera: https://help.opera.com/en/latest/web-preferences/#cookies
Some of the cookies used here are deleted again after you close your browser (so-called session cookies). Other cookies remain on your device and enable us or our partner companies (third-party cookies) to recognize your browser on your next visit (persistent cookies). If cookies are set, they collect and process certain user information to an individual extent, such as browser and location data as well as IP address values. Persistent cookies are automatically deleted after a predefined period, which may vary depending on the cookie.


4. Data processing for order handling

4.1. If you would like to place an order in our webshop, it is necessary for the conclusion of the contract that you provide your personal data, which we need to process your order. We process the data you provide to handle your order.

In some cases, we work with external service providers to process your order. For this purpose, we must pass on the personal data required for this.

If we commission transport companies to deliver your goods, we pass on the data required for delivery of the goods to the respective transport company. To process payments, we pass on your data to the commissioned credit institution to the extent necessary. If we use payment service providers, you will also be informed about this below.
The legal basis for the transfer of your data is Art. 6 (1) lit. b GDPR.

4.2. Use of payment service providers

- PayPal
If you select the payment method PayPal, credit card via PayPal, direct debit via PayPal or - if offered - "purchase on invoice" or "installment payment" via PayPal, payment processing is carried out via PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as "PayPal").
We pass on your personal data to PayPal in accordance with Art. 6 (1) lit. b GDPR to the extent necessary. PayPal reserves the right to carry out a credit check for the payment methods credit card via PayPal, direct debit via PayPal or - if offered - "purchase on invoice" or "installment payment" via PayPal.
For this purpose, your payment data may be passed on to credit agencies in accordance with Art. 6 (1) lit. f GDPR based on PayPal's legitimate interest in determining your ability to pay. PayPal uses the result of the credit check regarding the statistical probability of payment default for the purpose of deciding whether to provide the respective payment method.
The credit report may contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, but not exclusively, is included in the calculation of the score values.
Which other data is collected by PayPal can be found in PayPal's respective privacy policy. It can be found at: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.

- Shopify Payments
We use the payment service provider "Shopify Payments", 3rd Floor, Europa House, Harcourt Building, Harcourt Street, Dublin 2. If you choose a payment method offered via the payment service provider Shopify Payments, payment processing is carried out via the technical service provider Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, to which we pass on the information you provided during the ordering process along with the information about your order (name, address, account number, sort code, possibly credit card number, invoice amount, currency and transaction number) in accordance with Art. 6 (1) lit. b GDPR. Your data is passed on exclusively for the purpose of payment processing with Stripe Payments Europe Ltd. and only to the extent necessary for this purpose. Further information on data protection at Shopify Payments can be found at the following web address: https://www.shopify.com/legal/privacy
Data protection information on Stripe Payments Europe Ltd. can be found here: https://stripe.com/de/privacy

4.3. Google Pay
If you select the payment method "Google Pay" (a service of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google")), payment processing is handled via the "Google Pay" application on your Android mobile device (at least 4.4 "KitKat") equipped with an NFC function. Payment is made using one of your payment cards stored in Google Pay or a payment system verified there (e.g. PayPal). To authorize a payment via Google Pay of more than 25,- EUR, you must first unlock your mobile device. The information you provide during the order is passed on to Google for the purpose of payment processing. Google generates a one-time transaction number which is transmitted to the order website to verify the payment. This transaction number is merely a numeric token that contains no information about your data. The actual transaction is carried out between the user and the order website by charging the payment method stored with Google Pay. Personal data may be processed in the procedures described. In that case, processing is carried out for the purpose of payment processing in accordance with Art. 6 (1) lit. b GDPR.

Further information, in particular information on how Google handles your data, can be found here:
Google Pay Terms of Use https://payments.google.com/payments/apis-secure/u/0/get_legal_document?ldo=0&ldt =googlepaytos&ldl=de Google privacy policy: https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=pri vacynotice&ldl=de

5. Data processing when opening a customer account and for contract processing

If you open a customer account with us, personal data is collected and processed in accordance with Art. 6 (1) lit. b GDPR. The scope of the data can be seen from the input form. The data you enter is stored and used by us for contract processing.
You can delete your customer account at any time. This can be done by sending a message to the address of the controller or, if offered, directly in the customer account. In that case, we will also block your data with regard to retention periods under tax and commercial law and delete it after these periods have expired. This can only be prevented by your consent to permanent storage or by further use of the data permitted by law on our part.

6. Contact

If you contact us via the contact form, the data entered in the input form will be transmitted to us and stored. The data collected can be seen from the respective input form. When contacting us by email, only the data you entered there will be transmitted to us.
The data is used exclusively to process the conversation and your request. The legal basis for processing the data, if the user has given consent, is Art. 6 (1) lit. a) GDPR. The legal basis for processing the data transmitted in the course of sending an email is Art. 6 (1) lit. f) GDPR. If the email contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6 (1) lit. b) GDPR. The data is deleted as soon as it is no longer required for achieving the purpose for which it was collected, provided that no statutory retention obligations prevent this. For the personal data from the input form of the contact form and the data sent by email, this is the case when the respective conversation with the user has ended. The conversation has ended when it can be inferred from the circumstances that the matter in question has been conclusively clarified. The user may revoke consent to the processing of personal data at any time. If the user contacts us by email, they may object to the storage of their personal data at any time. In such a case, the conversation cannot be continued.

7. Use of single sign-on procedures

Facebook Connect Sign-in

We use "Facebook Connect" on our website, a plugin of the social network Facebook (Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA) (hereinafter referred to as "Facebook").
This allows you to register for the creation of a customer account or to log in using the so-called single sign-on technology if you have a Facebook profile. When you access one of our webpages that contains such a plugin, your browser establishes a direct connection to Facebook's servers. The content of the plugin is provided by Facebook
directly to your browser and integrated into the page. This gives Facebook the information that your browser has accessed the respective webpage, even if you do not have a Facebook profile or are not logged in to Facebook at that moment. This information (including your IP address) is transmitted directly from your browser to a Facebook server and stored there, whereby transmission to the USA is also possible.

Our legitimate interest lies in enabling a fast and uncomplicated registration process for our customers. The legal basis is therefore Art. 6 (1) lit. f GDPR.

Facebook's legitimate interest lies in displaying personalized advertising based on users' browsing behavior; the legal basis is therefore Art. 6 (1) lit. f GDPR.

You can also register and log in on our website with your Facebook data without using the Facebook button.

Only if you have given your express consent regarding the exchange of data with Facebook before the registration process in accordance with Art. 6 (1) lit. a GDPR, will we, when using the Facebook button, receive from Facebook the general and publicly accessible information stored in your profile. This transfer takes place only in accordance with your personal privacy settings on Facebook. This information includes, among other things, the user ID, name, profile picture, age, and gender.

Please note that following changes to Facebook's privacy policy and terms of use, granting consent may also result in the transfer of your profile pictures, your friends' user IDs, and your friends list if you have marked these as "public" in your Facebook privacy settings.

The data transmitted to us by Facebook is stored and processed by us for the creation of a user account with the necessary data. Based on your consent, data (e.g. information about your browsing or purchasing behavior) may also be transferred by us to your Facebook profile.

The consent granted can be revoked at any time by sending a message to the controller responsible for processing your data.

Further information can be found in Facebook's privacy policy: http://www.facebook.com/policy.php

If you do not want Facebook to associate the data collected on our website with your Facebook profile, you must log out of Facebook before visiting our website.

You can also completely prevent Facebook plugins from loading by using add-ons for your browser, for example "Adblock Plus" (https://adblockplus.org/de/).

8. Use of your data for direct advertising

8.1. Newsletter

Our website offers the option to subscribe to a free newsletter. When registering for the newsletter, the data from the input form is transmitted to us. The only mandatory information is your email address. If you provide further information voluntarily, it will only be used for personal addressing.

The legal basis for processing your data after registration for the newsletter, if the user has given consent, is Art. 6 (1) lit. a GDPR. We obtain this consent by sending you a confirmation email after newsletter registration containing a confirmation link. By clicking this link, you also grant consent to receive the newsletter.
When you send your newsletter registration, we store your IP address as well as the date and time of registration. This storage serves to be able to trace possible misuse of your email address.

We use the data collected by us when registering for the newsletter exclusively for the purpose of sending the newsletter.

You can cancel your newsletter subscription at any time. For this purpose, each newsletter contains a corresponding link. This also enables you to revoke consent to the storage of the personal data collected during the registration process.

8.2. Newsletter for existing customers

If you purchase goods or services on our website and provide your email address in the process, this email address may subsequently be used by us to send a newsletter. In such a case, the newsletter will only contain direct advertising for our own similar goods or services.

The legal basis for sending the newsletter following the sale of goods or services is Section 7 (3) UWG and Art. 6 (1) lit. f GDPR. Data processing is carried out solely on the basis of our legitimate interest in personalized direct advertising.

If you have already objected to the use of your email address for direct advertising purposes, you will not receive this newsletter. However, you also have the option at any time later to object to the use of your email address for the advertising purpose stated here with effect for the future by notifying us. After receipt of your objection, the use of your email address for advertising purposes will cease immediately.

8.3. Advertising by post

If, as part of an order with us, you have provided your first and last name, your postal address, and, if applicable, further personal data, we reserve the right, in order to safeguard our legitimate interest in personalized direct advertising pursuant to Art. 6 (1) lit. f GDPR, to store this data and send you our offers by post.

You can object to the storage and use of your data for this purpose at any time by sending a corresponding message to the controller.

9. Use of social media: social plugins

9.1. Facebook as a standard plugin

We use social plugins ("plugins") on our website from the social network Facebook (Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA) (hereinafter referred to as "Facebook") .

You can usually recognize the plugins by the Facebook logo, usually a white "f" on a blue background. You can view other versions of the Facebook plugin here:
https://developers.facebook.com/docs/plugins

When you access one of our webpages into which such a plugin is integrated, your browser establishes a direct connection to Facebook's servers and Facebook transmits the content of the plugin directly to your browser, even if you do not have a Facebook profile or are not currently logged into Facebook. This information (including your IP address) is transmitted directly from your browser to a Facebook server in the USA and stored there.

If you are logged into Facebook at the relevant time, Facebook can directly associate your visit to our website with your Facebook profile. If you interact with a plugin (e.g. click the "Like"/"like" button or comment on something), this information is also transmitted directly to a Facebook server and stored there. The actions may be published on your Facebook profile and displayed to your Facebook friends.

Our legitimate interest lies in displaying personalized advertising and in realizing the full financial potential of our website. The legal basis is Art. 6 (1) lit. f GDPR.

Facebook's legitimate interest lies in displaying personalized advertising and designing the service according to users' needs. The legal basis is therefore Art. 6 (1) lit. f GDPR.

If you do not want Facebook to associate the data collected via our website with your Facebook profile, you must log out of Facebook before visiting our website. You can also prevent Facebook plugins from loading by using add-ons for your browser, e.g. the script blocker "NoScript" (http://noscript.net/).

Further information can be found in Facebook's privacy policy:
http://www.facebook.com/policy.php

9.2. Instagram as a standard plugin

We use social plugins ("plugins") on our website from the social network Instagram (Instagram LLC., 1601 Willow Rd, Menlo Park, CA 94025, USA) (hereinafter referred to as "Instagram").

You can usually recognize the plugins by the "Instagram camera". You can view other versions of the Instagram plugin here: http://blog.instagram.com/post/36222022872/introducing-instagram-badges.

When you access one of our webpages into which such a plugin is integrated, your browser establishes a direct connection to Instagram's servers and Instagram transmits the content of the plugin directly to your browser, even if you do not have an Instagram profile or are not currently logged into Instagram. This information (including your IP address) is transmitted directly from your browser to an Instagram server in the USA and stored there.

If you are logged into Instagram at the relevant time, Instagram can directly associate your visit to our website with your Instagram profile. If you interact with a plugin (e.g. click the "Instagram" button or comment on something), this information is also transmitted directly to an Instagram server and stored there. The actions may be published on your Instagram profile and displayed to your Instagram friends.

Our legitimate interest lies in displaying personalized advertising and in realizing the full financial potential of our website. The legal basis is Art. 6 (1) lit. f GDPR.

Instagram's legitimate interest lies in displaying personalized advertising and designing the service according to users' needs. The legal basis is therefore Art. 6 (1) lit. f GDPR.

If you do not want Instagram to associate the data collected via our website with your Instagram profile, you must log out of Instagram before visiting our website. You can also prevent Instagram plugins from loading by using add-ons for your browser, e.g. the script blocker "NoScript" (http://noscript.net/).

Instagram privacy policy: https://help.instagram.com/155833707900388/

9.3. LinkedIn as a standard plugin

We use social plugins ("plugins") on our website from the social network LinkedIn (LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA) (hereinafter referred to as "LinkedIn").

You can usually recognize the plugins by the LinkedIn logo or the "Recommend button" ("Recommend").

When you access one of our webpages into which such a plugin is integrated, your browser establishes a direct connection to LinkedIn's servers and LinkedIn transmits the content of the plugin directly to your browser, even if you do not have a LinkedIn profile or are not currently logged into LinkedIn. This information (including your IP address) is transmitted directly from your browser to a LinkedIn server in the USA and stored there.

If you are logged into LinkedIn at the relevant time, LinkedIn can directly associate your visit to our website with your LinkedIn profile. If you interact with a plugin (e.g. click a "LinkedIn" button), this information is also transmitted directly to a LinkedIn server and stored there. The actions may be published on your LinkedIn profile and displayed to your LinkedIn friends.

Our legitimate interest lies in displaying personalized advertising and in realizing the full financial potential of our website. The legal basis is Art. 6 (1) lit. f GDPR.
LinkedIn's legitimate interest lies in displaying personalized advertising and designing the service according to users' needs. The legal basis is therefore Art. 6 (1) lit. f GDPR.
If you do not want LinkedIn to associate the data collected via our website with your LinkedIn profile, you must log out of LinkedIn before visiting our website. You can also prevent LinkedIn plugins from loading by using add-ons for your browser, e.g. the script blocker "NoScript" (http://noscript.net/).

LinkedIn privacy policy:
https://www.linkedin.com/legal/privacy-policy

10. Use of social media: video

10.1. Use of Vimeo videos

We integrate plugins from the Vimeo video portal of Vimeo, LLC, 555 West 18th Street, New York, New York 10011, USA, on our website.
If a page of our website containing such a plugin is accessed, the browser establishes a direct connection to Vimeo's servers. The content of the plugin is transmitted directly by Vimeo to your browser and integrated into the page. As a result, Vimeo receives the information that your browser has accessed the corresponding page (including your IP address). This also happens if you do not have a Vimeo account or are not currently logged into Vimeo. This information is transmitted directly to a Vimeo server in the USA and stored there.

If you are logged into Vimeo, Vimeo can directly associate your visit to our website with your Vimeo account. As soon as you interact with one of the plugins (e.g. by clicking the start button of a video), this information is also transmitted directly to a Vimeo server and stored there.

This data processing is carried out in accordance with Art. 6 (1) lit. a GDPR, namely your express consent.

To prevent the direct association of the data with your Vimeo account, you must log out of Vimeo before visiting our website.

The purpose and scope of data collection and the further processing and use of the data by Vimeo as well as your related rights and settings options for protecting your privacy can be found in Vimeo's privacy policy: http://vimeo.com/privacy

For videos from Vimeo embedded on this website, the tracking tool Google Analytics is automatically integrated. This is Vimeo's own tracking, to which we have no access and which cannot be influenced by us. Google Analytics uses "cookies" for tracking. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.

This processing is carried out in accordance with Art. 6 (1) lit. a GDPR on the basis of your express consent.

10.2. Use of YouTube videos

On this website, we use the YouTube embedding function to display and play videos from the provider "YouTube", which belongs to Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). We use the enhanced privacy mode, which according to the provider only starts storing user information when the video(s) are played. When you start playback of embedded YouTube videos, the provider "YouTube" uses cookies to collect information about your user behavior. According to "YouTube", these serve, among other things, to collect video statistics, improve user-friendliness, and prevent abusive behavior. If you are logged into Google at the same time, your data will be directly assigned to your account.

If you do not want this assignment to your YouTube profile, you must log out before activating the button. Google stores your data (even for users who are not logged in) as usage profiles and evaluates them.

Such an evaluation is carried out in particular in accordance with Art. 6 (1) lit.a GDPR on the basis of your express consent.

You have the right to object to the creation of these user profiles, although you must contact YouTube to exercise this right. Regardless of whether the embedded videos are played, a connection to the Google network "DoubleClick" is established every time this website is accessed, which may trigger further data processing operations beyond our control.

Data may also be transmitted to the servers of Google LLC. in the USA. Further information on data protection at "YouTube" can be found in the provider's privacy policy at: https://www.google.de/intl/de/policies/privacyOpt-out possible at:
https://adssettings.google.com/authenticated.

11. Online marketing

Use of Google Ads conversion tracking

This website uses the online advertising program "Google Ads" and, as part of Google Ads, conversion tracking by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").

This involves advertising our offers on external websites with the help of advertising material (so-called Google Adwords). Our legitimate interest lies in displaying advertising that is relevant to you and in achieving a fair calculation of advertising costs. The legal basis is Art. 6 (1) lit.a GDPR, namely your express consent.

Google Ads uses cookies for conversion tracking, which are set when you click on an AdWords ad placed by Google.

These cookies generally expire after 30 days and are not used for personal identification. Each Google Ads customer receives a different cookie, so cookies cannot be tracked across Ads customers' websites either.

The information obtained in this way is used to compile conversion statistics for Ads customers about the total number of users who clicked on their ad and were redirected to a page marked with a conversion tracking tag.

You cannot be personally identified through this.

If you want to prevent tracking, you can deactivate the Google conversion tracking cookie via your internet browser under user settings.

You can find information about Google's privacy policy here: http://www.google.de/policies/privacy/

You can permanently deactivate conversion cookies by setting your browser accordingly or by downloading and installing the browser plug-in available at the following link:
http://www.google.com/settings/ads/plugin?hl=de

In that case, certain functions of this website may not be usable or may only be usable to a limited extent.

12. Web analytics services

12.1. Google Analytics

We use the web analytics service Google Analytics (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland) for this website.
Google Analytics uses cookies". These are text files stored on your computer that enable analysis of your use of the website.
The information generated in this way about your use of this website (including the shortened IP address) is transmitted to a Google server and stored there, whereby transmission to the USA is possible.

We use Google Analytics with the extension "_anonymizeIp()", which ensures anonymization of the IP address by shortening it and excludes direct personal reference. Your IP address is therefore shortened by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server, including in the USA, and shortened there. In these exceptional cases, this processing is carried out in accordance with Art. 6 (1) lit. f GDPR. Our legitimate interest lies in the statistical analysis of user behavior for optimization and marketing purposes.

On our behalf, Google uses this information to evaluate your use of the website, compile reports on website activities, and provide us with further services related to website use and internet use. Your IP address collected in this context is not merged with other Google data.

For the purpose of optimized marketing of our website, we use the so-called user ID function. With the help of this function, we can assign a unique, permanent ID to your interaction data from one or more sessions on our online presence and thus analyze your user behavior across devices and sessions.

For web analytics and advertising purposes, the extension function of Google Analytics enables the so-called DoubleClick cookie to recognize your browser when visiting other websites. Google will use this information to compile reports on website activities and to provide further services related to website use.

You can prevent the storage of cookies by adjusting your browser settings accordingly.
You can also prevent the collection of the data generated by the cookie and related to your use of the website (including your IP address) and the processing of this data by Google by downloading and installing the following browser plug-in:
http://tools.google.com/dlpage/gaoptout?hl=de

Alternatively, you can set an opt-out cookie:

Disable Google Analytics

This opt-out cookie only works in this browser and only for this domain. If you delete your cookies in this browser, you must click this link again.

This website also uses Google Analytics for cross-device analysis of visitor flows, which is carried out via a user ID. You can deactivate the cross-device analysis of your use in your customer account under "My Data", "Personal Data".

Google privacy policy:
https://support.google.com/analytics/answer/6004245?hl=de

12.2. Shopify Analytics

We use Shopify's web analytics service (Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland).

To safeguard our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes, Shopify collects, evaluates, and stores pseudonymized visitor data from which pseudonymized usage profiles can be created and evaluated. Shopify uses cookies to recognize the browser and thus enable more precise determination of statistical data. Your IP address is also collected, but pseudonymized immediately after collection and before storage, so that personal reference is excluded.

The legal basis is Art. 6 (1) lit. a GDPR, namely your express consent.

Shopify does not combine your IP address with other Shopify data.

To object in the future to data collection and the creation of pseudonymized user profiles as well as the setting of cookies, you can generally deactivate the use of cookies on your computer by setting your internet browser so that no cookies can be stored on your computer in the future or cookies already stored can be deleted. However, disabling all cookies may mean that some functions on our website can no longer be used in full.

Shopify's privacy policies can also be found at:
https://www.shopify.de/legal/datenschutz

13. Retargeting / Remarketing / Referral advertising

13.1. Facebook Custom Audience via the pixel process

On this website, we use the "Facebook pixel" of Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook"). If express consent has been given, this can be used to track the behavior of users after they have seen or clicked on a Facebook ad. This process serves to evaluate the effectiveness of Facebook ads for statistical and market research purposes and can help optimize future advertising measures. The data collected is anonymous to us, so we cannot draw any conclusions about the identity of users. However, the data is stored and processed by Facebook, so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes in accordance with Facebook's data usage policy (https://www.facebook.com/about/privacy/).

You can enable Facebook and its partners to place ads on and outside Facebook. A cookie may be stored on your device for these purposes. These processing operations are carried out exclusively if express consent is granted in accordance with Art. 6 (1) lit. a GDPR. Consent to the use of the Facebook pixel may only be declared by users older than 13 years of age. If you are younger, please ask your legal guardians for permission. You can disable the use of cookies on your computer by changing your browser settings accordingly. However, this may result in some functions of our website no longer being fully usable. You can also disable the use of cookies by third parties such as Facebook on the following website of the Digital Advertising Alliance: http://www.aboutads.info/choices/

13.2. Google AdWords Remarketing

Our website uses the functions of Google Ads (formerly "Google AdWords") Remarketing; with this, we advertise this website in Google search results and on third-party websites. The provider is Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (hereinafter referred to as "Google"). For this purpose, Google places a cookie in the browser of your device, which automatically enables interest-based advertising by means of a pseudonymous cookie ID and on the basis of the pages you visited, and usually expires after 30 days. Processing is based on our legitimate interest in the optimal marketing of our website and in realizing the financial potential of our website. The legal basis is Art. 6 (1) lit. a GDPR, namely your express consent.

Further data processing only takes place if you have agreed with Google that your internet and app browsing history will be linked by Google to your Google account and that information from your Google account will be used to personalize ads you view on the web. If in this case you are logged into Google during your visit to our website, Google uses your data together with Google Analytics data to create and define audience lists for cross-device remarketing. For this purpose, your personal data is temporarily linked by Google with Google Analytics data in order to form audiences.

You can permanently disable the setting of cookies for ad preferences by downloading and installing the browser plug-in available at the following link: https://www.google.com/settings/ads/onweb/

Alternatively, you can visit the Digital Advertising Alliance at www.aboutads.info to find out about the setting of cookies and make settings in this regard. Finally, you can configure your browser so that you are informed about the setting of cookies and can decide individually whether to accept them or exclude the acceptance of cookies for certain cases or in general. If cookies are not accepted, the functionality of our website may be limited.

Privacy policies regarding advertising and Google:
https://policies.google.com/technologies/ads?hl=de

14. Use of a live chat system

14.1. Crisp

On this website, we use the live chat system of Crisp IM SAS, 2 Boulevard de Launay, 44100 Nantes, France, (www.crisp.chat).
Anonymized data is collected and stored for the purpose of web analytics and for operating the live chat system to answer live support inquiries. Pseudonymous user profiles can be created from this anonymized data. Cookies may also be used for this purpose. These cookies enable recognition of the internet browser. If the information collected in this way has a personal reference, the legal basis for processing is Art. 6 (1) lit. f GDPR.

Our legitimate interest lies in effective customer service and the statistical analysis of user behavior for optimization purposes. Without the consent of the data subject, the data is not used to personally identify the visitor to this website. No data is merged with personal data about the bearer of the pseudonym.

You can prevent the storage of cookies by setting your internet browser so that no cookies can be stored on your computer in the future or cookies already stored are deleted. However, this may mean that some functions on our website can no longer be carried out.

You have the option to object at any time with future effect to the collection and storage of data for the purpose of creating a pseudonymized user profile. Send us your objection informally by email to the email address stated at the beginning of this privacy policy.

15. Tools and miscellaneous

15.1. Google reCAPTCHA

We use the reCAPTCHA function from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google") in accordance with Art. 6 (1) lit. f GDPR based on our legitimate interest in preventing misuse and spam.
reCAPTCHA is a function intended to ensure that an entry is made by a natural person.
The service transmits your IP address and, if applicable, other data required by Google for the reCAPTCHA service to Google.

When using Google reCAPTCHA, your personal data may also be transmitted to the servers of Google LLC. in the USA.

Details on Google reCAPTCHA and Google's privacy policy can be viewed at:
https://www.google.com/intl/de/policies/privacy/

15.2. Google Maps
We use "Google Maps" (API) from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").

Google Maps is used to display interactive maps and create directions. By using Google Maps, information about the use of this website, including your IP address and the (starting) address entered as part of the route planner function, may be transmitted to Google. When you access a webpage on our website that contains Google Maps, your browser establishes a direct connection to Google's servers. The map content is transmitted directly by Google to your browser and integrated into the webpage by it. Therefore, we have no influence on the scope of the data collected by Google in this way. To the best of our knowledge, this includes at least the following data:
• Date and time of the visit to the relevant webpage,
• Internet address or URL of the accessed webpage,
• IP address, (starting) address entered as part of route planning.

We have no influence on the further processing and use of the data by Google and therefore cannot assume responsibility for this. If you are logged into Google, your data is assigned directly to your Google account. If you do not want this assignment, you must log out of Google. Google stores your data (including that of users who are not logged in) as usage profiles and evaluates them. Such an evaluation is carried out in accordance with Art. 6 (1) lit. a GDPR on the basis of your express consent.

If you do not want Google to collect, process, or use data about you via our website, you can also disable JavaScript in your browser settings. In this case, however, you cannot use the map display. The purpose and scope of data collection and the further processing and use of the data by Google as well as your related rights and settings options for protecting your privacy can be found in Google's privacy policy (https://policies.google.com/privacy?hl=de).

Google's terms of use can be accessed here:
http://www.google.de/intl/de/policies/terms/regional.html
the terms of use for Google Maps can be accessed here:
https://www.google.com/intl/de_US/help/terms_maps.html
Further information on data protection can be found here:
http://www.google.de/intl/de/policies/privacy/

15.3. Google Web Fonts

We use so-called web fonts provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google") for the consistent display of fonts.
As soon as you access our website, your browser loads the required web fonts into the browser cache.

For this, your browser must establish a connection to Google's servers, whereby your IP address is transmitted to Google. In this case, your personal data may also be transmitted to the servers of Google LLC. in the USA.
The legal basis is Art. 6 (1) lit. a GDPR, namely your express consent.

If your browser does not support web fonts or you reject their use, a standard font from your computer will be used.

Details on Google Web Fonts can be found here:
https://developers.google.com/fonts/faq
as well as in Google's privacy policy:
https://www.google.com/policies/privacy/

15.4. CloudFlare.

We use the provider Cloudflare (CloudFlare, Inc. 665 3rd St. #200, San Francisco, CA 94107, USA). CloudFlare offers a globally distributed content delivery network with DNS.
With the help of a CDN, large files, graphics, and scripts can be delivered more quickly and efficiently via regional servers connected over the internet. User data is processed only for the aforementioned purposes and to maintain the security and functionality of the CDN. For this purpose, the browser you use must connect to the CDN servers. As a result, your IP address is transmitted to the server. Under certain circumstances, Cloudflare also stores cookies on your computer with your permission in accordance with Art. 6 lit. a GDPR.

We have concluded a corresponding data processing agreement with Cloudflare on the basis of the GDPR and the EU standard contractual clauses.

Cloudflare may collect statistical data about visits to this website.
The following is collected:
Name of the accessed webpage, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address, and the requesting provider.
Cloudflare uses the log data for statistical evaluations for the purpose of operation, security, and optimization of the offering.Further information on data protection at Cloudflare can be found at the following link:
https://www.cloudflare.com/de-de/privacypolicy/

16. Rights of the data subject

16.1. Under applicable data protection law, you have comprehensive data subject rights vis-à-vis the controller with regard to the processing of your personal data (rights of access and intervention), which we inform you about below:

- Right of access pursuant to Art. 15 GDPR:
You may request confirmation from the controller as to whether personal data concerning you is being processed by the controller. Furthermore, you have a right of access to the purpose, the categories of personal data, the recipients, the planned storage period, and the existence of further rights such as rectification of the data or the existence of a right to lodge a complaint with a supervisory authority, the origin of your data if it was not collected by us, the existence of automated decision-making including profiling and, if applicable, meaningful information about the logic involved and the significance and intended consequences of such processing for you, as well as your right to be informed of the safeguards pursuant to Art. 46 GDPR in the event your data is transferred to third countries;

- Right to rectification pursuant to Art. 16 GDPR:
You have the right to immediate rectification of inaccurate data concerning you and/or completion of incomplete data stored by us; the rectification or completion must be carried out without delay.

- Right to restriction of processing pursuant to Art. 18 GDPR:
You have the right to request restriction of the processing of your personal data while the accuracy of your data that you contest is being verified, if you refuse the deletion of your data due to unlawful data processing and instead request restriction of the processing of your data, if you need your data for the establishment, exercise, or defense of legal claims after we no longer need this data for achieving the purpose, or if you have objected for reasons arising from your particular situation as long as it has not yet been determined whether our legitimate grounds override yours;
If the processing of personal data concerning you has been restricted, such data may - apart from storage - only be processed with your consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State. If the restriction of processing has been restricted, you will be informed by the controller before the restriction is lifted.

- Right to erasure pursuant to Art. 17 GDPR:
You have the right to request the immediate deletion of your personal data if the conditions of Art. 17 (1) GDPR are met. However, this right to deletion does not apply in particular - not exhaustively - if the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims

- Right to information pursuant to Art. 19 GDPR:
If you have exercised your right to rectification, erasure, or restriction of processing, the controller is obliged to communicate this rectification or erasure of the data or restriction of processing to all recipients to whom your personal data has been disclosed, unless this proves impossible or involves disproportionate effort. You also have the right to be informed about these recipients.

- Right to data portability pursuant to Art. 20 GDPR:
You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format or to request transmission to another controller, insofar as this is technically feasible;

- Right of withdrawal pursuant to Art. 7 (3) GDPR:
You have the right to object at any time to the processing of personal data concerning you that is carried out on the basis of Art. 6 (1) lit. e) or f) GDPR; this also applies to profiling based on these provisions.
You also have the right to withdraw your declaration of consent under data protection law at any time with effect for the future. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

- Right to lodge a complaint pursuant to Art. 77 GDPR:
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your place of residence, your place of work, or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.

16.2. Right to object

You have the right to object to the processing of your data at any time with effect for the future if we process your data based on our overriding legitimate interest following a balancing of interests.
If you exercise this right to object, we will stop processing your data unless compelling legitimate grounds for continuing the processing can be demonstrated which override your interests, rights, and freedoms, or if the further processing serves the establishment, exercise, or defense of legal claims.

17. Storage period of personal data

The storage period of personal data depends in each case on statutory retention periods. After these periods expire, we routinely delete the data if it is no longer required for contract fulfillment or contract initiation and/or if we no longer have a legitimate interest in continued storage.