Privacy Policy
The following data protection declaration provides you with a detailed overview of how your personal data is processed when you visit our website www.strosek.de.
This website is jointly operated by Strosek GmbH (hereinafter jointly referred to as STROSEK).
Data Protection for Website Users
§ 1 Contact Details of the Persons Responsible and the Data Protection Officer
The purposes pursued by the data controllers in the context of their respective business activities are listed in section 1.1.
1.1 Name and address of the responsible persons
The persons responsible within the meaning of the EU General Data Protection Regulation (GDPR) and other national data protection laws of the member states as well as other data protection regulations for the operation of these websites as well as the processing of personal data of visitors to the websites caused thereby is Strosek GmbH:
Strosek GmbH
Alter Hof 5
80331 München
Deutschland
Tel: +49 89 599 1824 00
E-Mail: info@strosek.de
Website: www.strosek.de
Within the scope of its business activities, Strosek GmbH is responsible for the sale of STROSEK models.
If you have any questions about your personal data, please contact: info@strosek.de.
1.2 Contact data protection officer
You can contact our data protection officer at: info@strosek.de
§ 2 General Information on the Collection of Personal Data
In principle, the collection, processing and use of personal data for the use of our website is limited to the necessary extent and the necessary data. Personal data is all data that can be related to you personally, e.g. name, address, e-mail addresses, user behavior. In addition, we use the widespread SSL procedure (Secure Socket Layer) on our website in conjunction with the highest level of encryption supported by your web browser. As a rule, this is 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. You can tell whether an individual page of our website is transmitted in encrypted form by the closed display of the key or lock symbol in the lower status bar of your browser.
§ 3 Purposes and Legal Bases of the Processing of your Personal Data and Further Information on Specific Data Processing
3.1 Processing of your data when visiting our website
3.1.1 Description and scope of data processing
Each time you visit our website, our system automatically collects data and information from the computer system of the calling computer (personal data transmitted by your browser to our server). This is also the case if you do not register or otherwise transmit information to us. The following data is collected:
- IP address of the user
- Date and time of the request or access
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request (specific page)
- Access status/HTTP status code
- Amount of data transferred in each case
- Website from which the request comes (from which the user’s system accesses our website)
- Website that is called up by the user’s system via our website
- Information about the type of browser and the version used
- Operating system and its interface
- Language and version of the browser software
3.1.2 Purposes of data processing
The processing of the aforementioned data, in particular the IP address by the system, is necessary and required to enable the delivery of the website to your computer. Further purposes are to ensure system security and system stability.
3.1.3 Legal basis for data processing
The legal basis for the temporary storage of data is Art. 6 para. 1 lit. f GDPR. Our legitimate interest follows from the purposes for data collection listed above. In no case do we use the collected data for the purpose of drawing conclusions about your person.
3.1.4 Duration of storage
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the collection of data for the provision of the website, this is regularly the case when the respective session has ended.
3.1.5 Possibility of objection and elimination
The collection of data for the provision of the website and the storage of the data in log files is absolutely necessary for the operation of the website. Consequently, there is regularly no possibility of objection on your part.
3.2 Data protection when using the contact form
3.2.1 Description and scope of data processing
On our website, we offer every visitor the opportunity to contact us via a contact form by providing personal data.
The following data is compulsorily collected from you when contacting us via the contact form:
- IP address
- Date and time of the message
- Your name
- E-mail address
- Subject of message
In addition, you can provide further voluntary information:
- Information in a file attachment
Whether and to what extent you provide us with additional personal data in the file attachment and we process it cannot be controlled by us at first. However, unless necessary, we ask you not to send us any personal data in the file attachments.
3.2.2 Purposes of data processing
The processing of your data is solely for the purpose of handling and responding to your inquiry. The specification of your e-mail address is necessary in order to be able to contact you. Your name is used to personalize your inquiry or reply and for internal allocation within our company.
3.2.3 Legal basis for data processing
If you have given your consent, the legal basis for processing your data is Art. 6 Para. 1 S. 1 lit. a GDPR. If the inquiry already serves the fulfillment of a contract to which you are a party or the implementation of pre-contractual measures, the additional legal basis for the processing of the data is Art. 6 para. 1 sentence 1 lit. b GDPR. In order to allocate your inquiry to our company, a further legal basis is the protection of our legitimate interests, Art. 6 Para. 1 lit. f GDPR; our legitimate interests follow from the purposes described, whereby we assume that your interests do not outweigh ours.
3.2.4 Duration of storage; possibility of objection and elimination
The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. This is particularly the case if your inquiry has been finally processed and, if applicable, answered. If the purpose of contacting you is already the implementation of a contract to which you are a party or the implementation of a pre-contractual measure, then the data will be deleted when it is no longer necessary for the implementation of the contract. It may also be necessary to store personal data in order to comply with contractual or legal obligations or to protect our legitimate interests. If the processing of your data is based on your consent, you have the option of revoking this consent. By clicking on the corresponding checkbox (opt-in) before transmitting your entered data to us, you consent to the processing of your data in accordance with this data protection declaration. If the data is also required for the fulfillment of a contract or for the implementation of pre-contractual measures, premature deletion of the data is only possible insofar as contractual or legal obligations do not prevent deletion.
3.3 Use of Cookies
When you visit and use our website, cookies are stored on your computer. Cookies are text files that are stored in the internet browser or by the internet browser on the user’s computer system. When a user calls up a website, a cookie may be stored on the user’s operating system. This cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is called up again.
Some of them are essential, i.e. they are technically required for the operation of our website. Other cookies are used for statistical purposes or to analyze access to our website or for marketing purposes or to offer you the use of external media. Both temporary/session cookies and longer stored cookies (so-called permanent cookies) are used. Temporary cookies are deleted as soon as you close your browser. Permanent cookies remain for a longer period of time, but can be deleted manually at any time. Some of the cookies are placed by third parties.
The legal basis for data processing when using essential cookies is Art. 6 Para. 1, S. 1 lit. f GDPR or Art. 25 Para. 2 No. 2 TTDSG, when using all other cookies the legal basis is your consent according to Art. 6 Para. 1, S. 1 lit. a GDPR or § 25 Para. 1 TTDSG. If we do not process your data on the basis of your explicit consent, your personal data will only be processed to the extent that this is necessary to protect our legitimate interests or the legitimate interests of a third party and your interests or fundamental rights and freedoms, which require the protection of personal data, do not take precedence.
Detailed information about the use of the respective cookies, in particular about their purpose, the respective function duration and the extent to which they are placed by third parties or third parties have access to the data collected via the cookies, can be found in our „Cookie Settings“ in addition to the information provided in our data protection declaration. Here you will also find detailed information on the legal basis for the respective data processing, depending on the category of cookies used.
You can consent to the use of the respective categories of cookies individually; you can also change your consent at any time under the „Cookie Settings“ or revoke it with respect to us.
§ 4 Hosting of the Websites (SiteGround)
4.1 Description and scope of data processing
These websites are hosted by the web hosting service Site Ground. The service provider is the Spanish company SiteGround Spain S.L., Calle de Prim 19, 28004 Madrid, Spain (hereinafter “SiteGround”). Web hosting is the provision of storage capacity and the hosting of websites on the web server of the web hosting service.
The personal data collected on our website is stored on the servers of the hosting provider. This may include but is not limited to
- IP addresses
- contact details
- Meta and communication data
- contract data
- website traffic
and other data generated via a website and presented in the context of this privacy policy.
We have concluded an order processing agreement with the hosting provider, which ensures that the data collected in this way is processed exclusively in accordance with our instructions and in compliance with the GDPR and the TTDSG. We have located our hosting servers exclusively in the Federal Republic of Germany to ensure that your personal data is only processed in a country with a high level of data security. In the case of data processing by SiteGround, however, it cannot be completely ruled out that personal data may be transferred to the USA and the United Kingdom, as SiteGround operates affiliated companies there within the group of companies. In this case, we have agreed with SiteGround within the framework of the concluded order processing contract that the requirements of the GDPR for a transfer to so-called third countries must be complied with (see below).
4.2 Purposes of data processing
The storage of the above-mentioned data, in particular the IP address, by our systems is only carried out temporarily for the duration of the session and is necessary to ensure the proper operation and presentation of the websites. We also use SiteGround to display our websites in a way that allows you to access our website without problems. We also want to secure our website against the influence of unauthorised third parties and improve it regularly.
4.3 Legal basis
4.3.1 Legal basis for data processing
The use of SiteGround is in our interest to ensure a stable and appealing presentation and accessibility of our website for you. This constitutes a legitimate business interest within the meaning of Art. 6 (1) p. 1 lit. f) GDPR.
4.3.2 Legal basis in the event of data transfer to a third country
As described, in the case of data processing by SiteGround, it cannot be completely ruled out that personal data will be transferred to the USA and the United Kingdom, as SiteGround operates affiliated companies there within the group of companies. In each case, Your personal data will be transferred to the USA and the United Kingdom on the basis of the available adequacy decision described at
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_de
Subject to legal or contractual permissions, personal data may only be processed in a third country if the special prerequisites of Art. 44 et seq. GDPR are met. Accordingly, data may be transferred in particular if the European Commission has determined by way of a decision within the meaning of Article 45 (1) and (3) of the GDPR that an adequate level of data protection is provided in the third country concerned. By means of such so-called adequacy decisions, the European Commission certifies a level of data protection in third countries that is comparable to the recognized standard in the European Economic Area (a list of these countries and a copy of the adequacy decisions can be found here: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_de).
Insofar as a data transfer takes place between the USA or the United Kingdom and the EU, it should be noted that such an adequacy decision exists for the USA and the United Kingdom. The data protection agreement (USA) and the adequacy decision (United Kingdom) can be found at Adequacy decision EU-US Data Privacy Framework_en.pdf (europa.eu) as well as EUR-Lex – L:2021:360:TOC – EN – EUR-Lex (europa.eu). The decisions state that the US and the UK will ensure an adequate level of protection – comparable to that of the European Union – for personal data.
US companies can become certified under the new data protection agreement by committing to comply with specified data protection requirements, including, for example, obligations to delete personal data when it is no longer necessary for the purpose for which it was collected and to ensure the continuity of protection when personal data is disclosed to third parties. A list of all certified US companies can be found at https://www.dataprivacyframework.gov/s/participant-search.
SiteGround (SG Hosting Inc.) is certified under the new US data protection agreement.
The agreement introduces binding safeguards. It provides that access by US intelligence agencies to EU data will be limited to what is necessary and proportionate and that a Data Protection Review Court (DPRC) will be established to which EU data subjects will have access. For example, if the DPRC finds that the new safeguards have been breached in the collection of the data, it can order the deletion of the data. The safeguards in the area of government access to data complement the obligations that US companies importing data from the EU must comply with.
Data subjects have several remedies if their data is not handled properly by US companies. These include free independent dispute resolution mechanisms and an arbitration board.
In addition, the data protection agreement provides certain safeguards regarding access by US authorities to data transferred within the data protection agreement, in particular for access for law enforcement and national security purposes. Access to data is limited to what is necessary and proportionate to protect national security.
EU data subjects have access to an independent and impartial redress mechanism, including referral to a data protection review tribunal, in relation to the collection and use of their data by US intelligence agencies. This tribunal independently investigates and resolves complaints, including by ordering binding remedies.
4.4 Duration of storage
Your personal data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the collection of data for the provision of the website, this is the case when the respective session has ended.
4.5 Further information
Further information on the purpose and scope of the data collection and its processing, as well as further information on your rights in this regard and setting options for protecting your privacy, can be obtained at the above address and at https://de.siteground.com/privacy.htm?tid=331668599105.
§ 5 Integration of YouTube Videos
5.1 Description and scope of data processing
We have integrated YouTube videos into our online offer, which are stored on http://www.YouTube.de or http://www.YouTube.com and can be played directly from our website. The service provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter “Google”).
When you visit our website, Google receives the information that you have accessed the corresponding sub-page of our website. In addition, the data that (as described above) is collected for technical reasons each time you visit our website will be passed on to Google.
The data transfer takes place regardless of whether Google provides a user account via which you are logged in or whether no user account exists. If you are logged in to YouTube, your data will be directly assigned to your account. If you do not wish your data to be associated with your YouTube profile, you must log out of YouTube before activating the button. Google stores your data as usage profiles and uses them for the purposes of advertising, market research and/or designing its website to meet your needs. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, and you must contact Google to exercise this right.
5.2 Purposes of data processing
The data processing, in particular the data transfer to Google, is carried out for the purpose of simplifying the use of our media content and increasing the attractiveness of our website. By integrating YouTube films, we give you the opportunity to interact with the social network YouTube and other users of this network, so that we can improve our offer and make it more interesting for you as a user.
5.3 Legal basis for data processing
5.3.1 Legal basis for storing and reading information in terminal equipment
Google can analyze and evaluate the user behavior of the data subject via so-called “tracking”. Tracking is data processing for the purpose of tracking the individual behavior of users on websites (usually across websites). Tracking is technically possible by identifying users through the use of so-called cookies, web bugs, JavaScripts or browser fingerprinting.
According to § 25 para. 1 p. 1 TTDSG in conjunction with. Art. 6 para. 1 p. 1 lit. a) GDPR, the storage and readout of information on or from an end device, irrespective of the personal reference of the information, generally requires the consent of the person concerned. This includes, for example, the reading of browser information such as screen resolution, operating system versions or installed fonts by means of a JavaScript code, from which a unique and long-lasting (hash) value is formed and transmitted to a server (see above “browser fingerprinting”). Furthermore, this includes the setting or placement of so-called “cookies” (see section 3.3 on the term “cookie”), unless the use of the cookie is absolutely necessary for the operation of the website. Furthermore, the technical reading of cookies that have already been set requires the consent of the person concerned.
Google uses the above technologies to analyze and evaluate the user behavior of the data subject to the extent described in section 4.1.
Your personal data for the analysis and evaluation of your user behavior to the extent described in section 4.1 and for the purposes described in section 4.2 will only be processed if you have given us your explicit and voluntary consent in accordance with Art. 6 para. 1 sentence 1 lit. a) GDPR.
You can revoke your consent at any time with effect for the future (see § 17).
5.3.2 Legal basis for the transfer of personal data to a third country
Your personal data will be transferred to the USA on the basis of an adequacy decision available at
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_de.
Subject to legal or contractual permissions, personal data may in principle only be processed in a third country if the special prerequisites of Art. 44 et seq. GDPR are met. Accordingly, data may be transferred in particular if the European Commission has determined by way of a decision within the meaning of Article 45 (1) and (3) of the GDPR that an adequate level of data protection is provided in the third country concerned. The European Commission certifies third countries by means of such so-called adequacy decisions a level of data protection that is comparable to the recognized standard in the European Economic Area (a list of these countries, as well as a copy of the adequacy decisions, can be found here: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_de).
Insofar as a data transfer takes place between the USA and the EU, it should be noted that such an adequacy decision exists for the USA. The European Commission adopted its adequacy decision for the new EU-US data protection agreement on 10 July 2023. The data protection agreement and the adequacy decision can be found at Adequacy decision EU-US Data Privacy Framework_en.pdf (europa.eu). The decision states that the US will ensure an adequate level of protection – comparable to that of the European Union – for personal data transferred from the EU to US companies within the scope of the new data protection agreement.
US companies can become certified under the new data protection agreement by committing to comply with specified data protection requirements, including, for example, obligations to delete personal data when it is no longer necessary for the purpose for which it was collected and to ensure continued protection when personal data is transferred to third parties. A list of all certified US companies can be found at https://www.dataprivacyframework.gov/s/participant-search.
Google is certified under the new data protection agreement.
The agreement introduces binding safeguards. It provides that access by US intelligence agencies to EU data will be limited to what is necessary and proportionate and that a Data Protection Review Court (DPRC) will be established to which EU data subjects will have access. For example, if the DPRC finds that the new safeguards have been breached in the collection of the data, it can order the deletion of the data. The safeguards in the area of government access to data complement the obligations that US companies importing data from the EU must comply with.
Data subjects have several remedies if their data is not handled properly by US companies. These include free independent dispute resolution mechanisms and an arbitration board.
In addition, the data protection agreement provides certain safeguards regarding access by US authorities to data transferred within the data protection agreement, in particular for access for law enforcement and national security purposes. Access to data is limited to what is necessary and proportionate to protect national security.
EU data subjects have access to an independent and impartial redress mechanism, including referral to a data protection review tribunal, in relation to the collection and use of their data by US intelligence agencies. This tribunal independently investigates and resolves complaints, including by ordering binding remedies.
5.4 Duration of storage, possibility of objection and removal at YouTube (company of the Google/Alphabet group of companies)
We have no influence on the data collected and the data processing procedures, nor are we aware of the full extent of the data collection, the purposes of the processing or the storage periods. We also have no information on the deletion of the collected data by Google. Google may store your personal data as a user profile and use it for advertising, market research and/or to tailor its website to your needs. Such an evaluation is carried out in particular (also for users who are not logged in) for the display of needs-based advertising and in order to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, and to exercise this right you must contact Google. For further information on the purpose and scope of data collection and processing by YGoogle, please refer to the provider’s privacy policy. There you will also find further information on your rights in this regard and possible settings for the protection of your privacy.
5.5 Further information
Further information on the purpose and scope of the data collection and its processing, as well as further information on your rights in this regard and on how to protect your privacy, can be obtained from: Google Ireland Limited Gordon House, Barrow Street Dublin 4 and at https://policies.google.com/privacy?hl=en.
§ 6 Services of Google Analytics
6.1 Description and scope of data processing
We use Google Analytics on our website, a web analysis service provided by Google LLC (“Google”), 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Analytics uses cookies that enable your use of the website to be analyzed. The information generated by the cookie about your use of this website (including your shortened IP address) is usually transmitted to a Google server in the USA and stored there.
We have activated IP anonymization on this website. Your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before transmission. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there.
The data is used to evaluate your use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage.
6.2 Legal basis
Your data is processed on the basis of your consent in accordance with Art. 6 para. 1 sentence 1 lit. a) GDPR. You can revoke your consent at any time with effect for the future by adjusting the cookie settings or using the browser add-on to deactivate Google Analytics.
6.3 Storage period
The data sent by us is automatically deleted after 14 months. Data whose retention period has been reached is automatically deleted once a month.
6.4 Objection to the collection of data
You can prevent the collection of your data by Google Analytics by adjusting your consent in the cookie settings or by installing the browser add-on available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de
6.5 Further information
Further information on the handling of user data by Google Analytics can be found in Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=de
§ 7 Services of Borlabs GmbH
7.1 Description and scope of data processing
We use the so-called Borlabs cookie on our website. Borlabs Cookie is a WordPress plugin that allows us to obtain permission to set cookies. For this purpose, we display a pop-up on our website that asks users for their consent via opt-in. The plug-in is provided by Borlabs GmbH, Rübenkamp 32, 22305 Hamburg Germany.
The following information is stored in the Borlabs cookie:
- Cookie duration
- Cookie version
- Domain and path of the WordPress website
- Consents
- UID (randomly generated ID)
The aforementioned information is not transmitted to Borlabs GmbH. The data is stored on our servers.
If you wish to withdraw your consent, simply delete the cookie in your browser. When you re-enter/reload the website, you will be asked again for your cookie consent.
Alternatively, you can adjust your consent at any time in the Cookie Settings.
7.2 Legal basis
The Borlabs cookie is absolutely necessary to operate our website. The legal basis is our legitimate interests pursuant to Art. 6 para. 1 p. 1 lit. f) GDPR for the purposes stated in section 5.1.
7.3 Storage period
The Borlabs cookie has a duration of one year.
7.4 Further information
You can find further information at: https://de.borlabs.io/borlabs-cookie/.
§ 8 Disclosure of Your Data to Third Parties
Except as set out above, we do not disclose personal data to any company, organization or person outside our company, except in one of the following circumstances:
8.1 With your consent
Insofar as already described in detail above, but in individual cases also beyond this, we pass on personal data to companies, organizations or persons outside our company if we have received your consent to do so (Art. 6 Para. 1, Sentence 1 lit. a, if applicable in conjunction with Art. 9 Para. 2 lit. a GDPR).
8.2 Processing by other bodies
We make personal data available to other companies that are associated with us in a group of companies, as well as to our third-party business partners, other trustworthy companies or persons who process it on our behalf. This is done on the basis of our instructions and in accordance with our data protection statement and other appropriate confidentiality and security measures.
8.3 For legal reasons
We will disclose personal data to companies, organizations or persons outside our company if we can reasonably assume that access to this data or its use, storage or disclosure is necessary, in particular, to comply with applicable laws, regulations or legal procedures or to comply with an enforceable official order; the legal basis in this respect is Art. 6 Para. 1, S. 1 lit. c in conjunction with Art. 9 Para. 2 lit. b GDPR. Art. 9 para. 2 lit. b GDPR.
8.4 Transfer of your data to a third country or an international organization
Unless expressly stated in this data protection declaration, your personal data will not be transferred to third countries (countries outside the EU or the EEA) or international organizations. However, within the framework of the jointly-used IT systems for the operation of the website, we also transfer your data to – as described in detail – Aristo AG, which is based in Switzerland. Switzerland has an appropriate level of data protection. This was determined by the EU Commission by means of an adequacy decision (pursuant to Article 45 of the GDPR).
§ 9 eCommerce and Payment Providers
Processing of Customer and Contract Data
We collect, process, and use personal customer and contract data for the purpose of establishing, structuring, and modifying our contractual relationships. Personal data regarding the use of this website (usage data) is collected, processed, and used only to the extent necessary to provide the user with access to the service or to process payment.
The legal basis for this is Article 6 (1) lit. b GDPR.
The collected customer data will be deleted after the completion of the order or the termination of the business relationship and the expiration of any statutory retention periods. Statutory retention periods remain unaffected.
Data Transfer at the Conclusion of Contracts for Online Shops, Merchants, and Goods Shipping
When you order goods from us, we will pass on your personal data to the transport company entrusted with the delivery and to the payment service provider responsible for payment processing. Only those data that are necessary for the respective service provider to fulfill their task will be disclosed. The legal basis for this is Article 6 (1) lit. b GDPR, which allows for the processing of data to fulfill a contract or pre-contractual measures. If you have given your consent under Article 6 (1) lit. a GDPR, we will pass your email address to the transport company entrusted with the delivery, so they can inform you by email about the shipping status of your order. You can withdraw your consent at any time.
Payment Services
We integrate third-party payment services on our website. When you make a purchase with us, your payment data (e.g., name, payment amount, bank account, credit card number) is processed by the payment service provider for payment processing. The respective terms and conditions and privacy policies of the providers apply to these transactions. The use of payment service providers is based on Article 6 (1) lit. b GDPR (contract processing) as well as in the interest of ensuring a smooth, convenient, and secure payment process (Article 6 (1) lit. f GDPR). If your consent is requested for certain actions, the legal basis for the data processing is Article 6 (1) lit. a GDPR; consents can be withdrawn at any time for the future.
The following payment services/payment service providers are used on this website:
PayPal
The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as “PayPal”).
Data transfer to the USA is based on the standard contractual clauses of the EU Commission.
You can find details here: https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full.
For details, refer to PayPal’s privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
Apple Pay
The provider of this payment service is Apple Inc., Infinite Loop, Cupertino, CA 95014, USA. You can find Apple’s privacy policy here: https://www.apple.com/legal/privacy/de-ww/.
Mollie
The provider of this payment service is Mollie B.V., Keizersgracht 126, 1015CW Amsterdam, Netherlands (hereinafter referred to as “Mollie”). With the help of Mollie, we integrate various payment methods on our website. For details, refer to Mollie’s privacy policy: https://www.mollie.com/de/privacy.
American Express
The provider of this payment service is American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany (hereinafter referred to as “American Express”). American Express may transmit data to its parent company in the USA. Data transfer to the USA is based on the Binding Corporate Rules. You can find details here: https://www.americanexpress.com/en-cz/company/legal/privacy-centre/binding-corporate-rules/.
For more information, refer to American Express’s privacy policy:
https://www.americanexpress.com/de-de/firma/legal/datenschutz-center/online-datenschutzerklarung/.
Mastercard
The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter referred to as “Mastercard”). Mastercard may transmit data to its parent company in the USA. Data transfer to the USA is based on Mastercard’s Binding Corporate Rules. You can find details here: https://www.mastercard.de/de-de/datenschutz.html and https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf.
VISA
The provider of this payment service is Visa Europe Services Inc., Branch London, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter referred to as “VISA”). The United Kingdom is considered a data protection-safe third country, meaning it has a level of data protection that is comparable to that of the European Union. VISA may transfer data to its parent company in the USA. Data transfer to the USA is based on the EU Commission’s standard contractual clauses. You can find details here: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zuzustandigkeitsfragen-fur-den-ewr.html.
For more information, refer to VISA’s privacy policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.
§ 10 Automated Decision-Making
Unless expressly described otherwise above, automated decision-making does not take place.
§ 11 Your Rights
You have the right:
- In accordance with Art. 15 GDPR, to request information about your personal data processed by us. In particular, you can request information about the processing purposes, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right of complaint, the origin of your data if it has not been collected by us, as well as about the existence of automated decision-making, including profiling, and, if applicable, meaningful information about its details;
- in accordance with Art. 16 GDPR, to request the correction of incorrect or incomplete personal data stored by us without delay;
- to request the erasure of your personal data stored by us in accordance with Art. 17 GDPR, unless the processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the assertion, exercise or defense of legal claims;
- in accordance with Art. 18 GDPR, to request the restriction of the processing of your personal data, insofar as the accuracy of the data is disputed by you, the processing is unlawful, but you object to its erasure and we no longer require the data, but you need it for the assertion, exercise or defense of legal claims or you have objected to the processing in accordance with Art. 21 GDPR;
- pursuant to Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request that it be transferred to another controller;
- to revoke your consent at any time in accordance with Art. 7 (3) GDPR. This means that we may no longer process the data based on this consent in the future; and
- complain to a supervisory authority in accordance with Art. 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters.
§ 12 Objection to or Revocation of the Processing of Your Data
If you have given your consent to the processing of your data, you may revoke this consent at any time in accordance with Art. 7 (3) GDPR. Such a revocation affects the permissibility of the processing of your personal data after you have expressed it to us.
Insofar as the processing of your personal data is based on our legitimate interests pursuant to Art. 6 (1) sentence 1 lit. f GDPR, you have the right to object to the processing pursuant to Art. 21 GDPR. This is the case if the processing is not necessary, in particular, for the fulfillment of a contract with you, which is shown by us in each case in the description of the functions. When exercising such an objection, we ask you to explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will review the situation and either discontinue or adjust the data processing or show you our compelling legitimate grounds on the basis of which we will continue the processing.
Of course, you can object to the processing of your personal data for advertising and data analysis purposes at any time. You can inform us of your objection to advertising using the contact details above.