Data Privacy

1. Data Protection

General Information

The following information provides a brief overview of what happens to your personal data when you visit this website. Personal data refers to any information that can be used to personally identify you. For detailed information on data protection, please refer to our Privacy Policy listed below.

Data Collection on this website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find the operator’s contact information in the “Information on the Data Controller” section of this Privacy Policy.

How do we collect your data??

Your data is collected, on the one hand, when you provide it to us. This may include, for example, data you enter into a contact form.

Other data is collected automatically or with your consent when you visit the website via our IT systems. This primarily consists of technical data (e.g., internet browser, operating system, or time of page view). This data is collected automatically as soon as you access this website.

What do we use your data for?

Some of the data is collected to ensure the website functions properly. Other data may be used to analyze your user behavior.

What rights do you have regarding your data?

You have the right at any time to receive, free of charge, information about the source, recipients, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you may revoke this consent at any time with future effect. Furthermore, under certain circumstances, you have the right to request the restriction of the processing of your personal data. You also have the right to file a complaint with the competent supervisory authority.

You may contact us at any time regarding this matter or any other questions about data protection.

Analytics Tools and Third-Party Tools

When you visit this website, your browsing behavior may be statistically analyzed. This is primarily done using so-called analytics programs.

Detailed information about these analytics programs can be found in the following privacy policy.

2. Hosting

We host the content of our website with the following provider:

External Hosting

This website is hosted externally. The personal data collected on this website is stored on the servers of the host(s). This may include, in particular, IP addresses, contact requests, meta and communication data, contract data, contact details, names, website visits, and other data generated via a website.

External hosting is carried out for the purpose of fulfilling our contractual obligations to our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of providing our online services securely, quickly, and efficiently through a professional provider (Art. 6(1)(f) GDPR). If consent has been obtained, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25(1) TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent may be revoked at any time.

Our hosting provider(s) will process your data only to the extent necessary to fulfill their service obligations and will follow our instructions regarding this data.

We use the following hosting provider(s):

Platform.sh GmbH 

Postfach 30 10 63

50780 Köln, Germany

Data Processing

We have entered into a data processing agreement (DPA) for the use of the aforementioned service. This is a contract required under data protection law that ensures the service provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

3. General Information and Mandatory Disclosures

Privacy Policy

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with applicable data protection laws and this Privacy Policy.

When you use this website, various types of personal data are collected. Personal data is data that can be used to personally identify you. This Privacy Policy explains what data we collect and how we use it. It also explains how and for what purpose this is done.

Please note that data transmission over the Internet (e.g., when communicating via email) may be subject to security vulnerabilities. It is not possible to completely protect data from access by third parties.

Information on the Data Controller

The data controller responsible for data processing on this website is:

Serengeti-Park Hodenhagen GmbH
Am Safaripark 1
29693 Hodenhagen

Telefon: +49 5164 / 97 99 0
E-Mail: info@serengeti-park.de

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g., names, email addresses, etc.).

Retention Period

Unless a more specific retention period is stated in this Privacy Policy, we will retain your personal data until the purpose for which the data is processed no longer applies. If you submit a valid request for erasure or revoke your consent to data processing, your data will be erased unless we have other legally permissible grounds for storing your personal data (e.g., retention periods under tax or commercial law); in the latter case, erasure will take place once these grounds no longer apply.

General Information on the Legal Basis for Data Processing on This Website

If you have consented to the data processing, we process your personal data on the basis of Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, provided that special categories of data as defined in Article 9(1) of the GDPR are being processed. In the event of explicit consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Article 49(1)(a) of the GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g., via device fingerprinting), data processing is additionally based on Section 25(1) of the German Teleservices Data Protection Act (TTDSG). Consent may be revoked at any time. If your data is necessary for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Article 6(1)(b) of the GDPR. Furthermore, we process your data if it is necessary to comply with a legal obligation on the basis of Article 6(1)(c) of the GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Article 6(1)(f) of the GDPR. The relevant legal bases in each individual case are described in the following sections of this Privacy Policy.

Data Protection Officer

We have appointed a Data Protection Officer:

Ralf Lohmann
HUBIT Datenschutz GmbH & Co. KG
Lise-Meitner-Str. 2
28359 Bremen

Telefon: +49 421-89830294
E-Mail: info@hubit.de

Recipients of Personal Data

As part of our business operations, we collaborate with various external parties. In some cases, this requires the transfer of personal data to these external parties. We only disclose personal data to external parties if this is necessary for the performance of a contract, if we are legally obligated to do so (e.g., disclosure of data to tax authorities), if we have a legitimate interest in the disclosure pursuant to Article 6(1)(f) of the GDPR, or if another legal basis permits the disclosure of data. When using data processors, we only transfer our customers’ personal data on the basis of a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.

Withdrawal of Your Consent to Data Processing

Many data processing operations are only possible with your explicit consent. You may withdraw any consent you have already provided at any time. The lawfulness of the data processing carried out prior to the withdrawal remains unaffected by the withdrawal.

Right to object to data collection in specific cases and to direct marketing (Art. 21 GDPR)

IF DATA PROCESSING IS BASED ON ART. 6(1)( E OR F OF THE GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. YOU CAN FIND THE SPECIFIC LEGAL BASIS ON WHICH PROCESSING IS BASED IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA, UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, exercise, or defense of legal claims (objection pursuant to Art. 21(1) GDPR).

IF YOUR PERSONAL DATA IS BEING PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING PURPOSES; THIS ALSO APPLIES TO PROFILING, TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the place where the alleged violation occurred. This right to lodge a complaint is without prejudice to any other administrative or judicial remedies.

Right to data portability

You have the right to have data that we process automatically based on your consent or in fulfillment of a contract provided to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent that it is technically feasible.

Access, Rectification, and Erasure

In accordance with applicable legal provisions, you have the right at any time to obtain, free of charge, information about your stored personal data, its origin and recipients, and the purpose of the data processing, as well as the right to have this data rectified or erased, if applicable. You may contact us at any time regarding this matter or any other questions about personal data.

Right to Restriction of Processing

You have the right to request the restriction of the processing of your personal data. You may contact us at any time regarding this matter. The right to restriction of processing applies in the following cases:

If you dispute the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of the verification, you have the right to request that the processing of your personal data be restricted.


If the processing of your personal data was or is unlawful, you may request that the processing be restricted instead of having the data erased.


If we no longer need your personal data, but you need it to exercise, defend, or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of erasure.


If you have lodged an objection pursuant to Article 21(1) of the GDPR, a balancing of your interests against ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, such data may—apart from storage—be processed only with your consent, or for the establishment, exercise, or defense of legal claims, or to protect the rights of another natural or legal person, or for reasons of an important public interest of the European Union or a Member State.

SSL or TLS Encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential information, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address bar of your browser changes from “http://” to “https://” and by the lock icon in your browser bar.

When SSL or TLS encryption is enabled, the data you transmit to us cannot be read by third parties.

Encrypted Payment Transactions on This Website

If, after entering into a paid contract, you are required to provide us with your payment details (e.g., account number for direct debit authorization), this information is necessary for processing the payment.

Payment transactions using standard payment methods (Visa/MasterCard, direct debit) are conducted exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection by the fact that the browser’s address bar changes from “http://” to “https://” and by the lock icon in your browser’s address bar.

With encrypted communication, the payment data you transmit to us cannot be read by third parties.

4. Data Collection on This Website: 

Cookies

Our website uses so-called “cookies.” Cookies are small data packets that do not cause any damage to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or your web browser deletes them automatically.

Cookies may originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain third-party services within websites (e.g., cookies for processing payment services).

Cookies serve various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies may be used to analyze user behavior or for advertising purposes.

Cookies that are necessary for the execution of the electronic communication process, for providing certain functions you have requested (e.g., the shopping cart function), or for optimizing the website (e.g., cookies for measuring website traffic) (necessary cookies), are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies to ensure the technically error-free and optimized provision of its services. If consent to the storage of cookies and similar recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Art. 6(1)(a) GDPR and § 25(1) TTDSG); consent may be revoked at any time.

You can configure your browser to notify you when cookies are set and to allow cookies only on a case-by-case basis, to block cookies in certain cases or generally, and to enable the automatic deletion of cookies when you close your browser. Disabling cookies may limit the functionality of this website.

You can find information about which cookies and services are used on this website in this Privacy Policy.

Consent via Usercentrics

This website uses Usercentrics’ consent technology to obtain your consent for the storage of certain cookies on your device or for the use of certain technologies, and to document this in compliance with data protection regulations. The provider of this technology is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, website: https://usercentrics.com/de/ (hereinafter “Usercentrics”).

When you visit our website, the following personal data is transmitted to Usercentrics:

Your consent(s) or the withdrawal of your consent(s)
Your IP address
Information about your browser
Information about your device
The time of your visit to the website
Geolocation

In addition, Usercentrics stores a cookie in your browser to associate the consents you have given—or their revocation—with your account. The data collected in this manner is stored until you request its deletion, delete the Usercentrics cookie yourself, or the purpose for storing the data no longer applies. Mandatory legal retention requirements remain unaffected.

Usercentrics is used to obtain the legally required consents for the use of certain technologies. The legal basis for this is Article 6(1)(c) of the GDPR.

Data Processing

We have entered into a data processing agreement (DPA) for the use of the aforementioned service. This is a contract required under data protection law that ensures the service provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Server Log Files

The website provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. This information includes:

Browser type and version
Operating system used
Referrer URL
Hostname of the accessing computer
Time of the server request
IP address

This data is not combined with other data sources.

The collection of this data is based on Art. 6(1)(f) of the GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website—for this purpose, the server log files must be collected.

Contact Form

If you submit inquiries to us via the contact form, we will store the information you provide in the form—including the contact details you enter there—for the purpose of processing your inquiry and in case we have follow-up questions. We will not share this data without your consent.

The processing of this data is based on Article 6(1)(b) of the GDPR, provided that your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries directed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if such consent was requested; consent may be revoked at any time.

The data you enter in the contact form will remain with us until you request that we delete it, revoke your consent to its storage, or the purpose for storing the data no longer applies (e.g., once your inquiry has been processed). Mandatory legal provisions—in particular retention periods—remain unaffected.

Inquiries via Email, Phone, or Fax

If you contact us via email, phone, or fax, your inquiry—including all personal data contained therein (name, inquiry)—will be stored and processed by us for the purpose of handling your request. We will not disclose this data without your consent.

The processing of this data is based on Article 6(1)(b) of the GDPR, provided that your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries directed to us (Article 6(1)(f) of the GDPR) or on your consent (Article 6(1)(a) of the GDPR) if such consent was requested; consent may be revoked at any time.

The data you send to us via contact requests will remain with us until you request its deletion, revoke your consent to its storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions—in particular statutory retention periods—remain unaffected.

Registration on this Website

You can register on this website to access additional features. We use the data you provide solely for the purpose of using the specific offer or service for which you have registered. The required information requested during registration must be provided in full. Otherwise, we will decline your registration.

For important changes, such as changes to the scope of services or technically necessary modifications, we will use the email address provided during registration to notify you.

The data entered during registration is processed for the purpose of fulfilling the user relationship established by the registration and, where applicable, to initiate further contracts (Art. 6(1)(b) GDPR) .

We will store the data collected during registration for as long as you remain registered on this website, after which it will be deleted. Statutory retention periods remain unaffected.

Sign Up with Google

Instead of registering directly on this website, you can sign up using Google. This service is provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

To sign up with Google, you simply need to enter your Google username and password. Google will verify your identity and confirm it to our website.

When you sign in with Google, we may be able to use certain information from your account to complete your profile with us. You decide whether and which information is used through your Google privacy settings, which you can find here: https://myaccount.google.com/security and https://myaccount.google.com/permissions.

The data processing associated with Google registration is based on our legitimate interest in providing our users with the simplest possible registration process (Art. 6(1)(f) GDPR). Since the use of the registration function is voluntary and users can decide for themselves on the respective access options, no conflicting overriding rights of the data subjects are apparent.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards when processing data in the United States. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please visit the provider’s website at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active 

5. Analytics Tools and Advertising

Google Tag Manager

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is a tool that allows us to integrate tracking or statistics tools and other technologies into our website. Google Tag Manager itself does not create user profiles, store cookies, or perform independent analyses. It serves solely to manage and deploy the tools integrated through it. However, Google Tag Manager records your IP address, which may also be transferred to Google’s parent company in the United States.

The use of Google Tag Manager is based on Article 6(1)(f) of the GDPR. The website operator has a legitimate interest in the quick and straightforward integration and management of various tools on its website. If consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent may be revoked at any time.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to complying with these data protection standards. For more information, please visit the provider’s website at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Google Analytics

This website uses features of the web analytics service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables the website operator to analyze the behavior of website visitors. In doing so, the website operator receives various usage data, such as page views, time spent on the site, operating systems used, and the user’s origin. This data is aggregated into a user ID and assigned to the website visitor’s respective device.

Furthermore, Google Analytics allows us to track your mouse and scroll movements and clicks, among other things. Google Analytics also uses various modeling approaches to supplement the collected data sets and employs machine learning technologies in data analysis.

Google Analytics uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google regarding the use of this website is generally transmitted to a Google server in the United States and stored there.

The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TTDSG. You may revoke your consent at any time.

Data transfers to the United States are based on the EU Commission’s Standard Contractual Clauses. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to complying with these data protection standards. You can obtain further information on this from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

IP Anonymization

Google Analytics IP anonymization is enabled. This means that Google will truncate your IP address within member states of the European Union or in other signatory states to the Agreement on the European Economic Area before transmitting it to the United States. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data

Browser Plugin

You can prevent Google from collecting and processing your data by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.

For more information on how Google Analytics handles user data, please refer to Google’s Privacy Policy: https://support.google.com/analytics/answer/6004245?hl=de.

Data Processing

We have entered into a data processing agreement with Google and fully comply with the strict requirements of German data protection authorities when using Google Analytics.

Google Analytics E-commerce Tracking

This website uses the “E-commerce Tracking” feature of Google Analytics. With the help of E-commerce Tracking, the website operator can analyze the purchasing behavior of website visitors to improve its online marketing campaigns. This involves collecting information such as orders placed, average order values, shipping costs, and the time from viewing a product to purchasing it. This data may be aggregated by Google under a transaction ID assigned to the respective user or their device.

Google Conversion Tracking

This website uses Google Conversion Tracking. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

With the help of Google Conversion Tracking, Google and we can determine whether a user has performed certain actions. For example, we can analyze which buttons on our website are clicked and how often, as well as which products are viewed or purchased particularly frequently. This information is used to generate conversion statistics. We learn the total number of users who clicked on our ads and what actions they performed. We do not receive any information that allows us to personally identify the user. Google itself uses cookies or similar recognition technologies for identification.

The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TTDSG. You may revoke your consent at any time.

For more information on Google Conversion Tracking, please refer to Google’s Privacy Policy: https://policies.google.com/privacy?hl=de.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards when processing data in the United States. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please visit the provider’s website at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Meta Pixel (formerly Facebook Pixel)

This website uses Facebook/Meta’s visitor action pixels to measure conversions. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the collected data is also transferred to the United States and other third countries.

This allows the behavior of site visitors to be tracked after they have been redirected to the provider’s website by clicking on a Facebook ad. This enables the effectiveness of Facebook ads to be evaluated for statistical and market research purposes and future advertising measures to be optimized.

The collected data is anonymous to us as the operator of this website; we cannot draw any conclusions about the identity of the users. However, the data is stored and processed by Facebook, allowing a connection to the respective user profile and enabling Facebook to use the data for its own advertising purposes in accordance with the Facebook Data Use Policy (https://de-de.facebook.com/about/privacy/). This enables Facebook to display advertisements on Facebook pages as well as outside of Facebook. As the site operator, we have no influence over this use of the data.

The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TTDSG. You may revoke your consent at any time.

We use the advanced matching feature within Meta Pixels. Advanced matching allows us to transmit various types of data (e.g., city, state, postal code, hashed email addresses, names, gender, date of birth, or phone number) about our customers and prospects, which we collect through our website, to Meta (Facebook). By activating this feature, we can tailor our Facebook advertising campaigns even more precisely to people who are interested in our offers. Advanced matching also improves the attribution of website conversions and enhances Custom Audiences.

To the extent that personal data is collected on our website and forwarded to Facebook using the tool described here, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). This joint responsibility is limited exclusively to the collection of the data and its transfer to Facebook. The processing carried out by Facebook after the transfer is not part of the joint responsibility. Our joint obligations are set out in a joint controllership agreement. You can find the text of the agreement at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Facebook tool and for the data protection-compliant implementation of the tool on our website. Facebook is responsible for the data security of its products. You can assert your data subject rights (e.g., requests for access) regarding data processed by Facebook directly with Facebook. If you assert your data subject rights with us, we are obligated to forward them to Facebook.

Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

Further information on protecting your privacy can be found in Facebook's Data Policy: https://de-de.facebook.com/about/privacy/.

You can also deactivate the "Custom Audiences" remarketing feature in the ad settings at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. You must be logged in to Facebook to do this.

If you do not have a Facebook account, you can deactivate Facebook's interest-based advertising on the European Interactive Digital Advertising Alliance website: http://www.youronlinechoices.com/de/praferenzmanagement/.

 

You can also deactivate the "Custom Audiences" remarketing feature in the ad settings at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

Facebook Conversion API

We have integrated the Facebook Conversion API into this website. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, the collected data is also transferred to the USA and other third countries.

The Facebook Conversion API allows us to record website visitors' interactions with our website and share this information with Facebook to improve advertising performance on Facebook.

For this purpose, the time of access, the visited webpage, your IP address and user agent, as well as potentially other specific data (e.g., purchased products, shopping cart value, and currency) are recorded. A complete overview of the data that can be collected can be found here: https://developers.facebook.com/docs/marketing-api/conversions-api/parameters.

The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TTDSG. You can withdraw your consent at any time.


To the extent that personal data is collected on our website and forwarded to Facebook using the tool described here, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). This joint responsibility is limited exclusively to the collection of the data and its transfer to Facebook. The processing carried out by Facebook after the transfer is not part of the joint responsibility. Our joint obligations are set out in a joint controllership agreement. You can find the text of the agreement at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Facebook tool and for the data protection-compliant implementation of the tool on our website. Facebook is responsible for the data security of its products. You can assert your data subject rights (e.g., requests for access) regarding data processed by Facebook directly with Facebook. If you assert your data subject rights with us, we are obligated to forward them to Facebook.

Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

Further information on protecting your privacy can be found in Facebook's Data Policy: https://de-de.facebook.com/about/privacy/.

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

Data Processing Agreement

We have concluded a data processing agreement (DPA) for the use of the aforementioned service. This is a legally required agreement under data protection law, which ensures that the provider processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.

6. Newsletter

Newsletter Data

If you wish to subscribe to the newsletter offered on this website, we require your email address and information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. No further data is collected, or only on a voluntary basis. We use newsletter service providers, described below, to process our newsletters.

Brevo

This website uses Brevo for sending newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.

Brevo is a service that, among other things, allows us to organize and analyze the sending of newsletters. The data you enter for the purpose of subscribing to the newsletter is stored on the servers of Sendinblue GmbH in Germany.

Data Analysis by Brevo

With the help of Brevo, we can analyze our newsletter campaigns. For example, we can see whether a newsletter message was opened and which links, if any, were clicked. This allows us to determine, among other things, which links were clicked most frequently.

We can also see whether certain predefined actions were performed after opening/clicking (conversion rate). For example, we can see if you made a purchase after clicking on the newsletter.

Brevo also allows us to segment ("cluster") newsletter recipients based on various categories. For example, recipients can be segmented by age, gender, or location. This allows us to better tailor the newsletters to specific target groups.

If you do not want Brevo to analyze your data, you must unsubscribe from the newsletter. We provide a corresponding link for this purpose in every newsletter message.

For detailed information about Brevo's features, please see the following link: https://www.brevo.com/de/newsletter-software/.

Legal Basis

Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw this consent at any time. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal.

Storage Period

The data you provide to us for the purpose of receiving the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after you unsubscribe. Data that has been stored by us for other purposes remains unaffected.

After you unsubscribe from the newsletter distribution list, your email address may be stored on a blacklist by us or the newsletter service provider if this is necessary to prevent future mailings. The data from the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage on the blacklist is not time-limited. You can object to this storage if your interests outweigh our legitimate interest.

For more information, please see Brevo's privacy policy at: https://www.brevo.com/de/datenschutz-uebersicht/ and https://www.brevo.com/de/legal/privacypolicy/.

Data Processing Agreement

We have concluded a data processing agreement (DPA) for the use of the aforementioned service. This is a legally required agreement under data protection law, which ensures that the service processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.

7. Plugins and tools

YouTube with Enhanced Privacy

This website embeds videos from YouTube. The website is operated by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

When you visit one of our websites that includes embedded YouTube videos, a connection to YouTube's servers is established. This informs the YouTube server which of our pages you have visited. If you are logged into your YouTube account, you allow YouTube to directly associate your browsing behavior with your personal profile. You can prevent this by logging out of your YouTube account.

We use YouTube in enhanced privacy mode. According to YouTube, videos played in enhanced privacy mode are not used to personalize your browsing experience on YouTube. Ads displayed in enhanced privacy mode are also not personalized. No cookies are set in enhanced privacy mode. Instead, so-called local storage elements are stored in the user's browser. These elements, similar to cookies, contain personal data and can be used for recognition purposes. Details on enhanced privacy mode can be found here: https://support.google.com/youtube/answer/171780.

Activating a YouTube video may trigger further data processing operations over which we have no control.

YouTube is used to enhance the presentation of our online content. This constitutes a legitimate interest within the meaning of Article 6(1)(f) GDPR. If consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) of the German Telecommunications and Telemedia Data Protection Act (TTDSG), insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be withdrawn at any time.

Further information about data protection at YouTube can be found in their privacy policy at: https://policies.google.com/privacy?hl=de.


The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Google Maps

This website uses the Google Maps service. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

To use the functions of Google Maps, it is necessary to store your IP address. This information is generally transmitted to and stored on a Google server in the USA. The provider of this website has no influence on this data transfer. When Google Maps is activated, Google may use Google Fonts for the purpose of consistent font display. When you access Google Maps, your browser loads the required web fonts into its browser cache to display texts and fonts correctly.

The use of Google Maps is in the interest of presenting our online services in an appealing way and making it easy to find the locations we have indicated on the website. This constitutes a legitimate interest within the meaning of Article 6(1)(f) GDPR. If corresponding consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) of the German Telecommunications and Telemedia Data Protection Act (TTDSG), insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be withdrawn at any time.

Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.

More information on how user data is handled can be found in Google's Privacy Policy: https://policies.google.com/privacy?hl=de.

The company is certified under the EU-US Data Privacy Framework (DPF). The Data Privacy Framework (DPF) is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

OpenStreetMap

We use the map service from OpenStreetMap (OSM).

We integrate the map data from OpenStreetMap on the server of the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom. The United Kingdom is considered a data protection-safe third country. This means that the United Kingdom has a level of data protection equivalent to that of the European Union. When using OpenStreetMap maps, a connection is established to the servers of the OpenStreetMap Foundation. This may involve transmitting your IP address and other information about your activity on this website to the OSMF. OpenStreetMap may store cookies in your browser or use similar recognition technologies for this purpose.

The use of OpenStreetMap is in the interest of presenting our online services in an appealing way and making it easy to find the locations we have indicated on the website. This constitutes a legitimate interest within the meaning of Article 6(1)(f) GDPR. If corresponding consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TTDSG, insofar as the consent includes the storage of cookies or access to information on the user's terminal equipment (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be withdrawn at any time.

Google reCAPTCHA

We use the "Google reCAPTCHA" service on our website to protect ourselves from spam and automated abuse. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

The legal basis for the use of reCAPTCHA is your consent pursuant to Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time with effect for the future.

The data processed by Google reCAPTCHA includes your IP address, browser information, operating system, cookies set by Google, and user interactions necessary to distinguish humans from bots.

The purpose of the data processing is to verify user interactions and to protect the website from spam and abuse.

It is possible that personal data may be transferred to insecure third countries (USA) where the level of data protection is lower than in the EU. Google is certified under the EU-US Data Privacy Framework, which regulates the secure processing of data of EU citizens in the USA. We have entered into a data processing agreement (DPA) with Google, which ensures that personal data is processed only according to our instructions and in compliance with the GDPR.

Fastly CDN

When you visit this website, personal data is processed. The data categories processed are: technical connection data of the server access (IP address, date, time, requested page, browser information). The purpose of the processing is to deliver and provide the website. The legal basis for the processing is a legitimate interest that overrides the rights and freedoms of the data subjects (Art. 6 (1) f GDPR). Legitimate interests in this context include a strong economic interest in the secure and functioning operation of the technical systems. Data is transferred to the data processor Fastly, Inc., 475 Brannan St, Suite 300, San Francisco, CA 94107, USA. This may also involve the transfer of personal data to a country outside the European Union. The transfer of data to the USA is based on Article 45 GDPR in conjunction with the European Commission's adequacy decision C(2023) 4745, as the data recipient has committed to complying with the data processing principles of the Data Privacy Framework (DPF). Information about Fastly, Inc.'s DPF membership can be found here.

8. eCommerce and payment providers

Processing of Customer and Contract Data

We collect, process, and use personal customer and contract data to establish, define the content of, and modify our contractual relationships. We collect, process, and use personal data relating to the use of this website (usage data) only to the extent necessary to enable the user to access the service or for billing purposes. The legal basis for this is Article 6(1)(b) GDPR.

The collected customer data will be deleted after completion of the order or termination of the business relationship and expiry of any applicable statutory retention periods. Statutory retention periods remain unaffected.

Data Transfer Upon Conclusion of a Contract for Online Shops, Retailers, and Shipping

When you order goods from us, we forward your personal data to the transport company entrusted with delivery and to the payment service provider commissioned with processing the payment. Only the data that the respective service provider needs to fulfill its task will be disclosed. The legal basis for this is Article 6(1)(b) GDPR, which permits the processing of data for the performance of a contract or for taking steps prior to entering into a contract. If you have given your consent pursuant to Article 6(1)(a) GDPR, we will pass your email address to the transport company entrusted with the delivery so that they can inform you about the shipping status of your order by email; you can withdraw this consent at any time.

Data Transfer During Contract Conclusion for Services and Digital Content

We only transfer personal data to third parties if this is necessary for contract processing, for example, to the credit institution commissioned with payment processing.

Data will not be transferred beyond this scope unless you have expressly consented to it. Your data will not be passed on to third parties without your express consent, for example, for advertising purposes.

The legal basis for data processing is Article 6 Paragraph 1 Letter b GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures.

Credit Checks

When purchasing on account or using another payment method where we provide services in advance, we may conduct a credit check (scoring). For this purpose, we transmit the data you entered (e.g., name, address, age, or bank details) to a credit agency. Based on this data, the probability of payment default is determined. If the risk of payment default is deemed excessive, we may refuse the payment method in question.


Credit Checks

When purchasing on account or using another payment method where we provide services in advance, we may conduct a credit check (scoring). Credit checks are carried out on the basis of contract fulfillment (Art. 6 para. 1 lit. b GDPR) and the prevention of payment defaults (legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR). If consent has been obtained, the credit check is carried out on the basis of this consent (Art. 6 para. 1 lit. a GDPR); this consent can be revoked at any time.

Payment Services

We integrate payment services from third-party companies on our website. When you make a purchase with us, your payment data (e.g., name, payment amount, bank account details, credit card number) is processed by the payment service provider for the purpose of payment processing. The respective terms and conditions and privacy policies of the respective providers apply to these transactions. The use of payment service providers is based on Art. 6 para. 1 lit. b GDPR (contractual necessity) and in the interest of ensuring the smoothest, most convenient, and most secure payment process possible (Art. 6 para. 1 lit. f GDPR). Where your consent is requested for specific actions, Art. 6 para. 1 lit. a GDPR is the legal basis for data processing; consent can be withdrawn at any time for the future.

We use the following payment services/payment service providers on this website:

PayPal

The provider of this payment service is PayPal (Europe) S.à.r.l. PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal").

Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full.

For details, please see PayPal's Privacy Statement: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

Apple Pay

The payment service provider is Apple Inc., Infinite Loop, Cupertino, CA 95014, USA. Apple's Privacy Statement can be found here: https://www.apple.com/legal/privacy/de-ww/.

Google Pay

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google's privacy policy can be found here: https://policies.google.com/privacy.

Stripe

The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (hereinafter "Stripe").

Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://stripe.com/de/privacy and https://stripe.com/de/guides/general-data-protection-regulation.

Further details can be found in Stripe's Privacy Policy at the following link: https://stripe.com/de/privacy.

American Express

The provider of this payment service is American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany (hereinafter "American Express").

American Express may transfer data to its parent company in the USA. Data transfers to the USA are based on the Binding Corporate Rules. Details can be found here: https://www.americanexpress.com/en-nl/company/legal/privacy-centre/european-implementing-principles/.

Further information can be found in the American Express Privacy Statement: https://www.americanexpress.com/de/legal/online-datenschutzerklarung.html.

Mastercard

The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter "Mastercard").

Mastercard may transfer data to its parent company in the USA. Data transfers to the USA are based on Mastercard's Binding Corporate Rules. Details can be found here: https://www.mastercard.de/de-de/datenschutz.html and https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf.


Mastercard VISA

This payment service is provided by Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter “VISA”).

The United Kingdom is considered a safe third country with regard to data protection. This means that the United Kingdom has a level of data protection equivalent to that of the European Union.

VISA may transfer data to its parent company in the USA. Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html.

Further information can be found in VISA's Privacy Policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.