Privacy policy

––––––––––––––––––––
Privacy Policy
––––––––––––––––––––

1) Introduction and Contact Details of the Data Controller
1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data is any data that can be used to personally identify you.

1.2 The data controller for this website within the meaning of the General Data Protection Regulation (GDPR) is Dennis Götz, eacygrow, Kapellenweg 3, 40882 Ratingen, Germany, Tel.: +49 2102 8918531, Email: support@eacygrow.com. The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.


2) Data Collection When You Visit Our Website
2.1 When you use our website for purely informational purposes, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the website server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:

- The website you visited
- Date and time of access
- Amount of data sent in bytes
- Source/referrer from which you accessed the page
- Browser used
- Operating system used
- IP address used (possibly in anonymized form)

This processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be disclosed or used for any other purpose. However, we reserve the right to subsequently review the server log files should there be concrete indications of unlawful use.

2.2 This website uses SSL/TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to us). You can recognize an encrypted connection by the "https://" prefix and the padlock icon in your browser's address bar.

3) Hosting & Content Delivery Network
3.1 Shopify
We use the system of the following provider to host our website and display its content: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify").

Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada.

All data collected on our website is processed on the provider's servers. We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

When data is transferred to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

3.2 Cloudflare

We use a Content Delivery Network from the following provider: Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA.

This service enables us to deliver large media files such as graphics, page content, or scripts more quickly via a network of regionally distributed servers. The processing is carried out to protect our legitimate interest in improving the stability and functionality of our website pursuant to Art. 6 para. 1 lit. f GDPR. We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision of the European Commission, ensures compliance with the European level of data protection.

3.3 Imgix

We use a Content Delivery Network (CDN) from the following provider: Zebrafish Labs Inc., 423 Tehama St., San Francisco, CA 94103, USA.

This service allows us to deliver large media files such as graphics, page content, or scripts more quickly via a network of regionally distributed servers. This processing is carried out to protect our legitimate interest in improving the stability and functionality of our website, in accordance with Art. 6 para. 1 lit. f GDPR. We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the EU-US Data Protection Framework.

European data protection standards are ensured.

4) Cookies

To make visiting our website attractive and to enable the use of certain functions, we use cookies, which are small text files that are stored on your device. Some of these cookies are automatically deleted after you close your browser (so-called "session cookies"), while others remain on your device for a longer period and allow us to save your website settings (so-called "persistent cookies"). In the latter case, you can find information about the storage period in your web browser's cookie settings.

If any of the cookies we use also process personal data, this processing is carried out in accordance with Article 6(1)(b) GDPR for the performance of the contract, in accordance with Article 6(1)(a) GDPR if you have given your consent, or in accordance with Article 6(1)(f) GDPR to protect our legitimate interests in ensuring the best possible website functionality and a user-friendly and effective website experience.


[Note: The last sentence about cookies appears to be incomplete and unrelated to the preceding text. It has been omitted from the translation.] You can configure your browser to notify you when cookies are being set and decide individually whether to accept them, or to block cookies in certain cases or entirely.

Please note that if you do not accept cookies, the functionality of our website may be limited.

5) Contacting Us
5.1 Judge.me
For review reminders, we use the services of the following provider: Judge.me Ltd., c/o Buckworths, 2nd Floor, 1-3 Worship Street, London, England, EC2A 2AB, United Kingdom.
Only with your explicit consent, in accordance with Article 6(1)(a) GDPR, will we transmit your email address and, if applicable, other customer data to the provider so that they can contact you with a review reminder via email.

You can withdraw your consent at any time with effect for the future by contacting us or the provider.

We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

When data is transferred to the provider's location, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

5.2 HubSpot
We use the services of the following provider to offer an online appointment booking function: HubSpot Ireland Ltd., 2nd Floor, 30 North Wall Quay, Dublin 1, Ireland.

For the purpose of scheduling appointments, in accordance with Article 6(1)(b) GDPR, your first and last name, email address (and, if applicable, your telephone number if you request a telephone appointment), are collected and, in accordance with Article 6(1)(f) GDPR, transmitted to the provider based on our legitimate interest in effective customer management and efficient appointment scheduling. This data is then stored there for appointment organization.

After the appointment has taken place or after the agreed appointment period has expired, your data will be deleted by the provider.

We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

5.3 When you contact us (e.g., via contact form or email), personal data is collected. The specific data collected when using a contact form is indicated on the form itself. This data is stored and used solely for the purpose of responding to your inquiry, contacting you, and for the associated technical administration.

The legal basis for processing this data is our legitimate interest in responding to your inquiry pursuant to Art. 6 para. 1 lit. f GDPR. If your contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted after your inquiry has been fully processed. This is the case when it is clear from the circumstances that the matter has been resolved and provided that no statutory retention obligations apply.


6) Data Processing When Opening a Customer Account

In accordance with Article 6(1)(b) GDPR, personal data will continue to be collected and processed to the extent necessary if you provide it to us when opening a customer account. You can find out which data is required for account opening in the input fields of the corresponding form on our website.

You can delete your customer account at any time by sending a message to the data controller's address listed above. After your customer account is deleted, your data will be deleted provided that all contracts concluded through it have been fully processed and no statutory retention periods apply.

and we no longer have a legitimate interest in further storage.

7) Use of Customer Data for Direct Marketing

7.1 Subscription to our Email Newsletter

When you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information required for sending the newsletter is your email address. Providing further information is voluntary and is used to personalize our communications with you. We use the so-called double opt-in procedure for sending the newsletter. This means that we will only send you an email newsletter after you have expressly confirmed that you consent to receiving it. We will then send you a confirmation email asking you to click on a corresponding link to confirm that you wish to receive the newsletter in the future.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 Para. 1 lit. a GDPR. When you subscribe to our newsletter, we store your IP address, which is registered by your Internet Service Provider (ISP), as well as the date and time of your subscription. This is to enable us to trace any potential misuse of your email address at a later date. The data we collect when you subscribe to our newsletter is used exclusively for sending you promotional emails. You can unsubscribe from the newsletter at any time by clicking the unsubscribe link in the newsletter or by sending a message to the data controller named above. After you unsubscribe, your email address will be immediately deleted from our newsletter mailing list, unless you have expressly consented to further use of your data or we reserve the right to use your data for other purposes permitted by law, which we will inform you about in this privacy policy.

7.2 Sending email newsletters to existing customers
If you provided us with your email address when purchasing goods or services, we reserve the right to regularly send you offers for similar goods or services from our product range via email. For this purpose, we do not need to obtain your separate consent in accordance with Section 7 Paragraph 3 of the German Unfair Competition Act (UWG). Data processing is based solely on our legitimate interest in personalized direct marketing pursuant to Article 6 Paragraph 1 Letter f of the GDPR. If you initially objected to the use of your email address for this purpose, we will not send you any emails.

You have the right to object to the use of your email address for the aforementioned advertising purpose at any time with effect for the future by sending a message to the data controller named at the beginning of this document. You will only incur transmission costs at the basic rates for this. Upon receipt of your objection, the use of your email address for advertising purposes will be discontinued immediately.

8) Data Processing for Order Fulfillment

8.1 To the extent necessary for contract fulfillment for delivery and payment purposes, the personal data we collect will be forwarded to the commissioned transport company and the commissioned bank in accordance with Article 6 Paragraph 1 Letter b of the GDPR.

If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we process the contact details you provided when placing your order (name, address, email address) in order to personally inform you about upcoming updates within the legally prescribed period, in accordance with our legal information obligations pursuant to Art. 6 para. 1 lit. c GDPR, via a suitable communication channel (e.g., by post or email). Your contact details will be used strictly for the purpose of notifying you about updates we owe you and will only be processed by us to the extent necessary for the respective information.

To process your order, we also work with the following service provider(s), who support us in whole or in part in fulfilling concluded contracts. Certain personal data will be transferred to these service providers in accordance with the following information.

8.2 Use of Payment Service Providers

Apple Pay
If you choose the "Apple Pay" payment method from Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, payment processing is handled via the "Apple Pay" function of your iOS, watchOS, or macOS device by charging a payment card stored with "Apple Pay." Apple Pay uses security features integrated into your device's hardware and software to protect your data.  

To protect transactions, you must enter a code you previously set and verify it using your device's Face ID or Touch ID function to authorize a payment.

For payment processing purposes, the information you provide during the ordering process, along with your order details, is transmitted to Apple in encrypted form. Apple then re-encrypts this data with a developer-specific key before transmitting it to the payment service provider of the payment card stored in Apple Pay. This encryption ensures that only the website where the purchase was made can access the payment data. After the payment is processed, Apple sends your device account number and a transaction-specific, dynamic security code to the originating website to confirm the payment.

If personal data is processed during these transmissions, it is processed exclusively for the purpose of payment processing in accordance with Article 6(1)(b) GDPR.


If personal data is processed during these transmissions, it is processed solely for the purpose of payment processing in accordance with Article 6(1)(b) GDPR. Apple retains anonymized transaction data, including the approximate purchase amount, date, and time, as well as whether the transaction was successful. Anonymization completely prevents any personal identification. Apple uses this anonymized data to improve Apple Pay and other Apple products and services.

When you use Apple Pay on your iPhone or Apple Watch to complete a purchase you made through Safari on your Mac, your Mac and the authorizing device communicate over an encrypted channel on Apple's servers. Apple does not process or store any of this information in a way that can identify you. You can disable the ability to use Apple Pay on your Mac in your iPhone's settings. Go to Wallet & Apple Pay and turn off Allow Payments on Mac.

Further information on data protection with Apple Pay can be found at the following web address: https://support.apple.com/de-de/HT203027

- Google Pay
If you choose the payment method "Google Pay" from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), payment processing will be handled via the "Google Pay" application on your mobile device, which must be running at least Android 4.4 ("KitKat") and have NFC capability. The payment will be charged to a payment card stored with Google Pay or a payment system verified there (e.g., PayPal). To authorize a payment via Google Pay exceeding €25, you must first unlock your mobile device using the verification method you have set up (such as facial recognition, password, fingerprint, or pattern).

For payment processing purposes, the information you provide during the ordering process, along with information about your order, will be shared with Google. Google then transmits your payment information stored in Google Pay to the originating website in the form of a unique transaction number, which is used to verify the payment. This transaction number contains no information about the actual payment details of your payment method stored in Google Pay, but is created and transmitted as a unique numerical token. In all transactions via Google Pay, Google acts solely as an intermediary for processing the payment. The transaction is executed exclusively between you and the originating website by debiting the payment method stored in Google Pay.

If personal data is processed during the described transmissions, this processing is carried out exclusively for the purpose of payment processing in accordance with Article 6(1)(b) GDPR.

Google reserves the right to collect, store, and analyze certain transaction-specific information for each transaction made via Google Pay. This includes the date, time, and amount of the transaction, the merchant's location and description, a description of the purchased goods or services provided by the merchant, photos you attached to the transaction, the name and email address of the seller and buyer or sender and recipient, the payment method used, your description of the reason for the transaction, and, if applicable, the offer associated with the transaction.

According to Google, this processing is carried out exclusively in accordance with Article 6(1)(f) GDPR on the basis of the legitimate interest in proper accounting, the verification of transaction data, and the optimization and maintenance of the Google Pay service.

Google also reserves the right to 

to combine the processed transaction data with other information that Google collects and stores when you use other Google services.


These transaction data are combined with other information that Google collects and stores when you use other Google services. You can find the Google Pay Terms of Service here:

https://payments.google.com/payments/apis-secure/u/0/get_legal_document?ldo=0&ldt=googlepaytos&ldl=de

Further information on data protection at Google Pay can be found at the following web address:

https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice&ldl=de

- Klarna
This website offers one or more online payment methods from the following provider: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden

If you select a payment method from this provider that requires you to pay in advance (such as credit card payment), your payment details provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number) as well as information about the contents of your order will be transmitted to them in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, your data will only be shared with the provider for the purpose of processing your payment and only to the extent necessary for this purpose.

If you select a payment method where the provider makes an advance payment (such as payment by invoice, installment plan, or direct debit), you will also be asked to provide certain personal data during the order process (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and, if applicable, details of an alternative payment method).

To protect our legitimate interest in assessing the creditworthiness of our customers, we forward this data to the provider for a credit check in accordance with Article 6 Paragraph 1 Letter f of the GDPR. Based on the personal data you provide, as well as other data (such as shopping cart contents, invoice amount, order history, and payment history), the provider checks whether your selected payment option can be granted with regard to payment and/or default risks.

For the purpose of the application review, in addition to internal provider criteria pursuant to Art. 6 para. 1 lit. f GDPR, identity and creditworthiness information from the following credit agencies may also be included:

https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies

The credit report may contain probability values (so-called score values). If score values are included in the credit report, they are based on a scientifically recognized mathematical-statistical method. Address data is among the data used to calculate the score values, but is not the only data used.

You can object to this processing of your data at any time by contacting us or the provider. However, the provider may still be entitled to process your personal data if this is necessary for processing payments in accordance with the contract.

- PayPal
This website offers one or more online payment methods from the following provider: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.

If you select a payment method from this provider where you pay in advance, your payment details provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number) as well as information about the contents of your order will be transmitted to them in accordance with Article 6 Paragraph 1 Letter b GDPR. In this case, your data will be transmitted exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

If you select a payment method where we pay in advance, you will also be asked to provide certain personal data during the ordering process (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and, if applicable, details of an alternative payment method).

In order to protect our legitimate interest in assessing your creditworthiness in such cases, we forward this data to the provider for the purpose of a credit check in accordance with Article 6(1)(f) GDPR. Based on the personal data you provided, as well as other data (such as shopping cart contents, invoice amount, order history, and payment history), the provider checks whether the payment option you selected can be granted with regard to payment and/or default risks.

 

The credit report may contain probability values (so-called score values). If score values are included in the credit report, they are based on a scientifically recognized mathematical-statistical method. Address data is among the data used to calculate the score values, but is not the only factor.

You can object to this processing 

You can object to the processing of your data at any time by sending us a message or contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for processing your payment in accordance with the contract.

- Shopify Payments
This website offers one or more online payment methods from the following provider: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.

If you select a payment method from the provider that requires you to pay in advance (such as credit card payment), your payment details provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number) as well as information about the contents of your order will be transmitted to the provider in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, your data will only be transmitted to the provider for the purpose of payment processing and only to the extent necessary for this purpose.

8.3 Electronic Termination Option for Continuing Obligations with Consumers

Consumers who have entered into contracts for paid continuing obligations (such as subscription contracts) on this website have the option to terminate these contracts electronically in accordance with the applicable notice periods.

Clicking the button leads to a confirmation page where the consumer can provide further details regarding the termination, clearly identify themselves, and then submit their termination electronically.

The collection of personal data and its transmission to us is carried out in accordance with Article 6(1)(b) GDPR and only to the extent necessary for the proper processing of the termination. Also based on Article 6(1)(b) GDPR, the provided personal data is used to confirm receipt of the termination notice and the termination date electronically in text form. A further legal basis for the processing is Article 6(1)(c) GDPR. We are legally obligated to provide an electronic cancellation option for consumer contracts concluded via electronic commerce concerning ongoing contractual obligations subject to fees.

9) Online Marketing
HubSpot

This website uses the software-based marketing service of the following provider for the provision and synchronization of various customer management services: HubSpot Ireland Ltd., 2nd Floor, 30 North Wall Quay, Dublin 1, Ireland.

The service enables the automated processing of feed activities, the control of advertising in the marketing channels used, and the analysis of the success of marketing measures, as well as centralized email marketing and contact management.

Cookies are used to fulfill the various functions. These are small text files that are stored locally in your web browser's cache on your device and allow us to analyze your use of the website. The cookies collect certain information, such as the IP address, location, and time of the page visit.

All processing described above, in particular the setting of cookies to read information on your device, will only be carried out if you have given us your explicit consent in accordance with Article 6(1)(a) GDPR. You can withdraw your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

Other legal bases for data processing that apply within the scope of specific service functions (such as the requirement of explicit consent in accordance with Article 6(1)(a) GDPR for sending newsletters) remain unaffected.

We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.


10) Web Analytics Services
10.1 Google Analytics 4

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which allows us to analyze your use of our website.

By default, Google Analytics 4 sets cookies when you visit the website. These cookies are small text files that are stored on your device and collect certain information. This information includes your IP address, which Google truncates by removing the last few digits to prevent it from being directly linked to you.

The information is transmitted to and processed on Google servers. This may also involve transfers to Google LLC, which is located in the USA.

Google uses the collected information on our behalf to evaluate website usage, compile reports on website activity for us, and provide other services related to website and internet usage, we use Google Analytics. The IP address transmitted by your browser as part of Google Analytics and shortened as part of this service will not be merged with other Google data. The data collected through the use of Google Analytics 4 is stored for two months and then deleted.

All processing described above, in particular the setting of cookies on your device, only takes place if you have given us your explicit consent in accordance with Art. 6 Para. 1 lit. a GDPR. Without your consent, Google Analytics 4 will not be used during your visit to our website. You can revoke your consent at any time with effect for the future. To exercise your right of revocation, please deactivate this service using the "Cookie Consent Tool" provided on the website.

We have concluded a data processing agreement with Google, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

Further legal information regarding Google Analytics 4 can be found at https://business.safety.google/intl/de/privacy/, https://policies.google.com/privacy?hl=de&gl=de, and https://policies.google.com/technologies/partner-sites

Demographics
Google Analytics 4 uses the special "demographics" feature to generate statistics that provide information about the age, gender, and interests of website visitors. This is achieved by analyzing advertising and information from third-party providers. This allows for the identification of target groups for marketing activities. However, the collected data cannot be attributed to any specific individual and is deleted after a storage period of two months.

Google Signals
As an extension to Google Analytics 4, Google Signals can be used on this website to generate cross-device reports. If you have enabled personalized ads and linked your devices to your Google account, Google can, subject to your consent to the use of Google Analytics pursuant to Art. 6 para. 1 lit. a GDPR, analyze your usage behavior across devices and create database models, including those related to cross-device conversions. We do not receive any personal data from Google, only statistics. If you wish to stop cross-device analysis, you can deactivate the "Personalized ads" feature in your Google account settings. To do so, follow the instructions on this page: https://support.google.com/My-Ad-Center-Help/answer/12155764?hl=de. You can find more information about Google Signals at the following link: https://support.google.com/analytics/answer/7532985?hl=de

UserIDs
As an extension to Google Analytics 4, the "UserIDs" feature may be used on this website. If you have consented to the use of Google Analytics 4.0 in accordance with Art. 6 para. 1 lit. a GDPR, have created an account on this website, and log in to this account on different devices, your activities, including conversions, can be analyzed across devices.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

10.2 Google Tag Manager

This website uses the “Google Tag Manager,” a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: “Google”).

The Google Tag Manager provides a technical basis for bundling various web applications, including tracking and analytics services, and for calibrating, controlling, and subjecting them to conditions via a unified user interface. The Google Tag Manager itself does not store or read any information on user devices. The service does not perform any independent data analysis. However, when you visit our website, Google Tag Manager transmits your IP address to Google, where it may be stored. Transmission to Google LLC servers in the USA is also possible.

This processing only occurs if you have given us your explicit consent in accordance with Article 6(1)(a) of the GDPR. Without this consent, Google Tag Manager will not be used during your visit. You can withdraw your consent at any time with effect for the future. To withdraw your consent, please deactivate this service in the "Cookie Consent Tool" provided on the website.

We have a data processing agreement with the provider. 

A data processing agreement has been concluded that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

Further legal information on Google Tag Manager can be found at https://policies.google.com/privacy?hl=de&gl=de.

11) Website Functionalities
Google Web Fonts
This website uses web fonts from the following provider for the uniform display of fonts: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

When you access a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly and establishes a direct connection to the provider's servers. In doing so, certain browser information, including your IP address, is transmitted to the provider.

Data may also be transferred to: Google LLC, USA

The processing of personal data during the connection process with the font provider will only take place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service via the "Cookie Consent Tool" provided on the website. If your browser does not support web fonts, a standard font from your computer will be used.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

12) Tools and Other
Cookie Consent Tool
This website uses a "Cookie Consent Tool" to obtain effective user consent for cookies and cookie-based applications that require consent. The "Cookie Consent Tool" will appear as an interactive user interface when you visit our website. You can grant consent for specific cookies and/or cookie-based applications by checking boxes. Using this tool, all cookies/services requiring consent will only be loaded if you grant the corresponding consent by checking the boxes. This ensures that such cookies are only placed on your device if you have given your consent.

The tool uses technically necessary cookies to save your cookie preferences. No personal user data is processed in this process.

If, in individual cases, personal data (such as the IP address) is processed for the purpose of storing, assigning, or logging cookie settings, this is done in accordance with Article 6 Paragraph 1 Letter f of the GDPR based on our legitimate interest in legally compliant, user-specific, and user-friendly cookie consent management and thus in the legally compliant design of our website.

A further legal basis for processing is Article 6(1)(c) GDPR. As the data controller, we are legally obligated to make the use of cookies that are not technically necessary contingent upon the respective user's consent.

Where necessary, we have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

Further information about the operator and the settings options of the cookie consent tool can be found directly in the corresponding user interface on our website.

13) Rights of the Data Subject
13.1 Applicable data protection law grants you the following rights as a data subject (rights of access and intervention) with regard to the processing of your personal data by us as the data controller. The respective requirements for exercising these rights are set out in the legal basis listed below:

- Right of access pursuant to Article 15 GDPR;

- Right to rectification pursuant to Article 16 GDPR;

- Right to erasure pursuant to Article 17 GDPR;

- Right to restriction of processing pursuant to Article 18 GDPR;

- Right to be informed pursuant to Article 19 GDPR;

- Right to data portability pursuant to Article 20 GDPR;

- Right to withdraw consent pursuant to Article 7(3) GDPR;

- Right to lodge a complaint pursuant to Article 77 GDPR.

13.2 Right to object
If we process your personal data based on our overriding legitimate interest as part of a balancing of interests, you have the right to object to this processing at any time on grounds relating to your particular situation.

To have an effect on the future.

If you exercise your right to object, we will cease processing the data in question. However, further processing remains possible if we can demonstrate compelling legitimate grounds for the processing which override your interests, fundamental rights and freedoms, or if the processing serves the establishment, exercise or defense of legal claims.

If we process your personal data for direct marketing purposes, you have the right to object to the processing of your personal data for such marketing at any time. You can exercise your right to object as described above.

If you exercise your right to object, we will cease processing the data in question for direct marketing purposes.

14) Duration of Storage of Personal Data
The duration of storage of personal data is determined by the respective legal basis, the purpose of processing, and – where applicable – the respective statutory retention period (e.g., commercial and tax law retention periods).

When processing personal data based on explicit consent pursuant to Article 6(1)(a) GDPR, the data in question will be stored until you withdraw your consent.

If statutory retention periods exist for data processed in connection with contractual or quasi-contractual obligations based on Article 6(1)(b) GDPR, this data will be routinely deleted after the retention periods have expired, unless it is still required for the performance of a contract or for taking steps prior to entering into a contract and/or we have a legitimate interest in its continued storage.

When processing personal data based on Article 6(1)(f) GDPR, this data will be stored until you exercise your right to object pursuant to Article 21(1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the purpose of establishing, exercising or defending legal claims.

When processing personal data for direct marketing purposes based on Article 6(1)(f) GDPR, this data will be stored until you exercise your right to object pursuant to Article 21(2) GDPR.

Unless otherwise specified in this privacy policy regarding specific processing situations, stored personal data will be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.

Copyright notice: This privacy policy was created by the specialist lawyers of the IT Law Firm and is protected by copyright (https://www.it-recht-kanzlei.de).

Last updated: December 1, 2025, 1:40:27 PM