Privacy policy Premio Fashion GmbH

We take data protection seriously

The protection of your privacy when processing personal data is an important concern for us. When you visit our website, our web servers store the IP of your Internet service provider, the website from which you visit us, the web pages you visit on our site and the date and duration of your visit as standard. This information is essential for the technical transmission of the web pages and secure server operation. There is no personalised analysis of this data.

If you send us data via the contact form, this data is stored on our servers as part of the data backup process. Your data will only be used by us to process your enquiry. Your data will be treated as strictly confidential. It will not be passed on to third parties.

Table of contents

1. WHO IS RESPONSIBLE FOR DATA PROCESSING AND WHO CAN YOU CONTACT?
2. PERSONAL DATA
3. VISITING THE WEBSITE
3.1. GENERAL USE
3.2. AUTOMATICALLY STORED DATA
3.3. CONTACTING US
3.4. CATALOGUE REQUEST
3.5. COOKIES
3.6. CONSENT MANAGEMENT
3.7. NEWSLETTER
3.8. HOSTING
3.9. FONTS
4. TOOLS AND SERVICES FOR ANALYSIS, STATISTICS AND MARKETING
4.1. ANALYSIS AND STATISTICS
4.2. ADVERTISING AND MARKETING
5. CUSTOMER ACCOUNT
5.1. SHOP AND E-COMMERCE
5.2. ECONOMIC ANALYSES AND MARKET RESEARCH
5.3. ANALYTICS UNION FOR END CUSTOMERS
5.4. PAYMENT SERVICE PROVIDERS
5.5. TRANSPORT SERVICE PROVIDERS
5.6. ADVERTISING AND LETTERSHOP
5.7 SOVENDUS
5.8. ACQUISITION OF NEW AND EXISTING CUSTOMERS
6. ONLINE PRESENCE ON SOCIAL MEDIA
7. SECURITY
8. WHAT DATA PROTECTION RIGHTS DO I HAVE?
9. CHANGES TO THIS PRIVACY POLICY

1. Who is responsible for data processing and who can you contact?

Responsible party:

Premio Fashion GmbH
Heinrich-Wirth-Straße 8
95213 Münchberg
Germany

www.madeleine.com/uk
service.uk@madeleine.com

The company data protection officer is

Mr Christian Volkmer
Project 29 GmbH & Co. KG
Ostengasse 14
93047 Regensburg
Germany

E-mail: anfragen@projekt29.de
Phone: +49 941-298 6 930

2. Personal data

Personal data is data about your person. This includes your name, your address and your e-mail address. You do not have to disclose any personal data in order to visit our website. In some cases, we need your name and address as well as other information in order to be able to offer you the requested service.

The same applies if we supply you with information material on request or if we answer your enquiries. In these cases, we will always point this out to you. Furthermore, we only store the data that you have transmitted to us automatically or voluntarily.

If you use one of our services, we generally only collect the data that is necessary to provide you with our service. We may ask you for further information, but this is voluntary. Whenever we process personal data, we do so in order to be able to offer you our service or to pursue our commercial objectives.

3 Visiting the website

3.1 General use

When you visit our website, our web servers store the IP of your internet service provider, the website from which you visit us, the web pages you visit on our site and the date and duration of your visit by default. The processing of this information is absolutely necessary for the technical transmission of the web pages, the convenient use of our services and the secure operation of the server Our legitimate interest arises from Art. 6 para. 1 lit. f) GDPR.

It is not possible to draw any direct conclusions about your identity from the information and we will not do so. The information is stored and automatically deleted once the aforementioned purposes have been achieved. The standard periods for erasure are based on the criterion of necessity.

3.2 Automatically stored data

Server log files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are

- Date and time of the request

- Name of the requested file

- Page from which the file was requested

- Access status (file transferred, file not found, etc.)

- Web browser and operating system used

- Complete IP address of the requesting computer

- Volume of data transferred

This data is not merged with other data sources. Processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website.

For reasons of technical security, in particular to defend against attempted attacks on our web server, this data is stored by us for a short period of time. It is not possible for us to identify individual persons from this data. After seven days at the latest, the data is anonymised by shortening the IP address at domain level so that it is no longer possible to establish a link to the individual user. The data is also processed in anonymised form for statistical purposes; it is not compared with other databases or passed on to third parties, even in excerpts.

3.3 Making contact

When contacting us (e.g. by contact form, email, telephone or via social media), the details of the person making the enquiry are processed insofar as this is necessary to respond to the contact enquiry and any measures requested.

The response to contact enquiries in the context of contractual or pre-contractual relationships is carried out to fulfil our contractual obligations or to respond to (pre)contractual enquiries and otherwise on the basis of the legitimate interests in responding to the enquiries.

• Processed data types: inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers), content data (e.g. entries in online forms).

• Data subjects: communication partners.

• Purposes of processing: contact requests and communication.

• Legal bases: contract fulfilment and pre-contractual enquiries (Art. 6 para. 1 lit. b. GDPR), legitimate interests (Art. 6 para. 1 lit. f. GDPR).

3.4. Catalogue request

You can request a current catalogue via our website. We process the following personal data from you for this purpose:

- First name, surname and address

The legal basis for the processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You will receive the latest edition of our catalogue until you withdraw your consent. Please note that if you revoke your consent or object to advertising, it may take some time before you no longer receive catalogues, as these are planned and printed in advance.

3.5. Cookies

When you visit our website, we may store information on your computer in the form of cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier of the cookie. It is a string of characters made of which websites and servers can be assigned to the specific Internet browser in which the cookie was stored. This enables the websites and servers visited to distinguish the individual browser of the data subject from other Internet browsers that contain other cookies. A specific Internet browser can be recognised and identified via the unique cookie ID.

3.6 Consent management

Usercentrics

This website uses the consent technology of Usercentrics to obtain your consent to the storage of certain cookies on your end device or to the use of certain technologies and to document these in compliance with data protection regulations. The provider of this technology is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany, website:

https://usercentrics.com/ (hereinafter referred to as "Usercentrics").

When you visit our website, the following personal data is transmitted to Usercentrics:

- Your consent(s) or the revocation of your consent(s)

- your IP address

- Information about your browser

- Information about your end device

- Time of your visit to the website

In addition, Usercentrics stores a cookie in your browser in order to be able to assign the consents given or their revocation to you. The data collected in this way is stored until you ask us to delete it, delete the Usercentrics cookie yourself or the purpose for storing the data no longer applies. Mandatory statutory retention obligations remain unaffected.

Usercentrics is used to obtain the legally required consent for the use of certain technologies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.

We have concluded a data processing agreement (DPA) in accordance with Art. 28 GDPR with the above-mentioned provider. This is a contract required by data protection law, which ensures that the provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.

3.7 Newsletter

Mailjet

This website uses Mailjet to send newsletters. The provider is Mailgun Technologies Inc, 112 E Pecan Sr #1135, San Antonio, Texas 78205, USA.

Mailjet is a service that can be used to organise and analyse the sending of newsletters, among other things. The data you enter for the purpose of subscribing to the newsletter is stored on Mailjet's servers.

With the help of Mailjet, we are able to analyse our newsletter campaigns. For example, we can see whether a newsletter message has been opened and which links have been clicked on. In this way, we can determine, among other things, which links were clicked on particularly often.

We can also recognise whether certain previously defined actions were carried out after opening/clicking (conversion rate). For example, we can recognise whether you have made a purchase after clicking on the newsletter.

Mailjet also enables us to categorise newsletter recipients according to various categories ("clustering"). Newsletter recipients can be categorised by age, gender or place of residence, for example. In this way, the newsletters can be better customised to the respective target groups. If you do not wish to be analysed by Mailjet, you must unsubscribe from the newsletter. We provide a link for this purpose in every newsletter message.

Detailed information on the functions of Mailjet can be found at the following link:

https://www.mailjet.de/funktion/.

You can find Mailjet's privacy policy at

https://www.mailjet.com/legal/security-privacy/.

Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time. The legality of the data processing operations that have already taken place remains unaffected by the revocation.

The data transfer to the USA is based on the standard contractual clauses of the EU Commission.

You can find details here:

https://www.mailjet.com/legal/dpa/.

The data you provide us with for the purpose of subscribing to the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and deleted from the newsletter distribution list after you unsubscribe from the newsletter. Data stored by us for other purposes remains unaffected by this.

After you unsubscribe from the newsletter distribution list, your email address will be stored by us or the newsletter service provider in a blacklist, if this is necessary to prevent future mailings.

The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage in the blacklist is not limited in time. You can object to the storage if your interests outweigh our legitimate interest.

We have concluded an order processing contract (AV) in accordance with Art. 28 GDPR with the above-mentioned provider. This is a contract prescribed by data protection law, which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

3.8 Hosting

Storyblok

We use the Storyblok service of the company Storyblok GmbH, Peter-Behrens-Platz 2, 4020 Linz, Austria, website: https://www.storyblok.com/.

The transmission and processing of personal data takes place exclusively on servers in the European Union.

The service is a plugin that we need in order to be able to show you all the content on our website. The service may also be used for tracking and/or advertising integration. For this reason, the legal basis is our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.

Further information on the handling of the transferred data can be found in the provider's privacy policy at https://www.storyblok.com/legal/privacy-policy.

3.9 Fonts

Fast Fonts

This website uses so-called web fonts provided by Monotype GmbH (fonts.com or fast.fonts.net) for the standardised display of fonts. When you call up a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly. For this purpose, the browser you are using must connect to the fonts.com servers. As a result, fonts.com becomes aware that our website has been accessed via your IP address. The use of fonts.com web fonts is in the interest of a uniform and appealing presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.

4 Tools and services for analysis, statistics and marketing

4.1 Analysis and statistics

Google Tag Manager

We use the Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The Google Tag Manager is a tool that we use to integrate tracking or statistical tools and other

technologies on our website. The Google Tag Manager itself does not create any user profiles, does not store any cookies and does not carry out any independent analyses. It is only used to manage and display the tools integrated via it. However, Google Tag Manager records your IP address, which may also be transmitted to Google's parent company in the United States.

The Google Tag Manager is used on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the fast and uncomplicated integration and management of various tools on its website. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting). Consent can be revoked at any time.

Google Analytics (4)

This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables the website operator to analyse the behaviour of website visitors. The website operator receives various usage data, such as page views, length of visit, operating systems used and origin of the user. This data is summarised in a user ID and assigned to the respective end device of the website visitor.

We can also use Google Analytics to record your mouse and scroll movements and clicks, among other things. Google Analytics also uses various modelling approaches to supplement the data records collected and uses machine learning technologies for data analysis.

Google Analytics uses technologies that enable the recognition of the user for the purpose of analysing user behaviour (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is generally transmitted to a Google server in the USA and stored there. The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR. Consent can be revoked at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here:

https://privacy.google.com/businesses/controllerterms/mccs/.

Browser plugin

You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link:

https://tools.google.com/dlpage/gaoptout?hl=en.

You can find more information on how Google Analytics handles user data in Google's privacy policy:

https://support.google.com/analytics/answer/6004245?hl=en.

Google signals

We use Google signals. When you visit our website, Google Analytics records your location, search history and YouTube history as well as demographic data (visitor data), among other things. This data can be used for personalised advertising with the help of Google Signals. If you have a Google account, the visitor data from Google Signal is linked to your Google account and used for personalised advertising messages. The data is also used to compile anonymised statistics on the user behaviour of our users.

Google Analytics e-commerce measurement

This website uses the "e-commerce measurement" function of Google Analytics. With the help of e-commerce measurement, the website operator can analyse the purchasing behaviour of website visitors to improve its online marketing campaigns. Information such as orders placed, average order values, shipping costs and the time from viewing to purchasing a product is recorded. This data can be summarised by Google under a transaction ID that is assigned to the respective user or their device.

Mouseflow

This website uses Mouseflow. The provider is Mouseflow Ltd, Flaesketorvet 68, 1711 Copenhagen V, Denmark (Europe) (website: https://www.mouseflow.com).

Mouseflow is a tool for analysing your user behaviour on this website. Mouseflow enables us to record your mouse and scroll movements and clicks, among other things. Mouseflow can also determine how long you remain with the mouse pointer in a particular position. Mouseflow uses this information to create so-called heat maps, which can be used to determine which website areas are favoured by website visitors. Furthermore, we can determine how long you stayed on a page and when you left it. We can also determine at which point you cancelled your entries in a contact form (so-called conversion funnels).

Mouseflow can also be used to obtain direct feedback from website visitors. This function serves to improve the website operator's web offerings. Mouseflow uses technologies that enable the recognition of the user for the purpose of analysing user behaviour (e.g. cookies or the use of device fingerprinting).

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal

4.2 Advertising and marketing

Google Ads

The website operator uses Google Ads. Google Ads is an online advertising programme of Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Ads enables us to display adverts in the Google search engine or on third-party websites when the user enters certain search terms in Google (keyword targeting). Furthermore, targeted adverts can be displayed based on the user data available at Google (e.g. location data and interests) (target group targeting). As the website operator, we can evaluate this data quantitatively by analysing, for example, which search terms led to the display of our advertisements and how many advertisements led to corresponding clicks.

The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR. Consent can be revoked at any time. Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https://policies.google.com/privacy/frameworks and

https://privacy.google.com/businesses/controllerterms/mccs/.

Google Remarketing / Google Customer Match

 On our website, we use the Google Ads retargeting feature to create remarketing lists based on the behaviour of users who have interacted with our website, YouTube channel, or advertising in order to display personalised advertising to these users within the Google advertising network.
We also use the Google Analytics retargeting feature by creating remarketing target groups based on our user data in Google Analytics and sharing them with Google Ads to display personalised advertising to these users within the Google advertising network.
Furthermore, by using Google Signals in Google Analytics, we can display personalised advertising to these users across devices within the Google advertising network if they are logged into their Google account and have activated ‘personalised advertising’.

We also use the Google Ads Customer Match function to create custom audiences based on our customer data, which enables us to reach potential and existing customers with personalised advertising within the Google advertising network.
We also use the Google Ads ‘Enhanced Conversions’ feature to optimise our advertising efforts on the Google advertising network by better identifying groups of people within the Google advertising network who are highly likely to perform conversion events (e.g. purchases) on our website. This is done by us sending your email address, which is known to us, to Google after you have carried out a conversion event (e.g. purchase) on our website.
The legal basis for the use of the retargeting, customer matching and advanced conversion functions of Google Ads is your consent in accordance with Art. 6 (1) paragraph a of the GDPR. You can withdraw your consent at any time by changing your cookie settings on our website accordingly.

Google AdSense (not personalised)

This website uses Google AdSense, a service for integrating adverts. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

We use Google AdSense in "non-personalised" mode. In contrast to personalised mode, the advertisements are therefore not based on your previous user behaviour and no user profile is created for you. Instead, so-called "contextual information" is used to select the adverts. The selected adverts are then based, for example, on your location, the content of the website you are on or your current search terms. You can find out more about the differences between personalised and non-personalised targeting with Google AdSense at

https://support.google.com/adsense/answer/9007336.

Please note that cookies or comparable recognition technologies (e.g. device fingerprinting) may also be used when using Google Adsense in non-personalised mode. According to Google, these are used to combat fraud and abuse. The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR. Consent can be revoked at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission.

You can find details here: https://privacy.google.com/businesses/controllerterms/mccs/.

You can customise your advertising settings yourself in your user account. To do this, click on the following link and log in: https://www.google.de/intl/de/policies/privacy/.

You can customise your advertising settings yourself in your user account. To do this, click on the following link and log in: https://adssettings.google.com/authenticated.

You can find more information about Google's advertising technologies here:

https://policies.google.com/technologies/ads and https://www.google.de/intl/de/policies/privacy/.

Microsoft Advertising

We use the Microsoft Advertising service provided by Microsoft Ireland Operations Limited (Ireland/EU) (formerly Bing Ads) on our website. Microsoft Advertising is an online marketing service that uses the Universal Event Tracking (UET) tool to help us display targeted adverts via the Microsoft Bing search engines. Microsoft Advertising uses cookies for this purpose. This involves processing personal data in the form of online identifiers (including cookie identifiers), IP addresses, device identifiers and information about device and browser settings.

Microsoft Advertising collects data via UET that we can use to track target groups thanks to remarketing lists. For this purpose, a cookie is stored on the end device used when you visit our website. This enables Microsoft Advertising to recognise that our website has been visited and to display an advertisement when Microsoft Bing or Yahoo is subsequently used. The information is also used to create conversion statistics, i.e. to record how many users have reached our website after clicking on an advert. This tells us the total number of users who clicked on our advert and were redirected to our website. However, we do not receive any information with which users can be personally identified.

Further information on these processing activities, the technologies used, stored data and the storage period can be found in the settings of our Consent Management Tool. Processing only takes place with your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent via our Consent Management Tool.

In the case of Microsoft services, the transfer of data to Microsoft Corp. in the USA cannot be ruled out. Please note the information in the section "Data transfer to third countries". Further information on data protection at Microsoft can be found in Microsoft's privacy policy at https://privacy.microsoft.com/de-de/privacystatement.

We also use the service's customer match feature to create custom audiences from our customer data, which allows us to reach potential and existing customers with personalised advertising within the advertising network.

Criteo

This website uses Criteo functions. The provider is Criteo SA, 32 Rue Blanche, 75009 Paris (hereinafter "Criteo").

Criteo is used to show you interest-based adverts within the Criteo advertising network. Your interests are determined on the basis of your previous usage behaviour. For example, Criteo records which products you have viewed, placed in your shopping basket or purchased. Further details on the data collected by Criteo can be found here: https://www.criteo.com/privacy/how-we-use-your-data/.

In order to be able to show you interest-based advertising, we or other Criteo partners must be able to recognise you. For this purpose, a cookie is stored on your end device or a comparable identifier is used, which links your user behaviour with a pseudonymous user profile. For details, please refer to Criteo's privacy policy at https://www.criteo.com/privacy/.

In addition, we use so-called Enhanced Match. This supplement organises the users' conversion data on the basis of the email addresses. In this process, encrypted email addresses are sent to Criteo in order to organise website special occasions.

Your personal data and the Criteo cookies stored in your browser are stored for a maximum of 13 months from the date of collection.

Criteo is used in the interest of targeted advertising. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting). Consent can be revoked at any time.

Criteo and we are joint controllers within the meaning of Art. 26 GDPR. An agreement on joint processing has been concluded between Criteo and us, the main contents of which Criteo describes under the following link https://www.criteo.com/privacy/how-we-use-your-data/.

We also use the service's customer match feature to create custom audiences from our customer data, which allows us to reach potential and existing customers with personalised advertising within the advertising network.

Facebook Pixel

This website uses Facebook's visitor action pixel to measure conversions. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the data collected is also transferred to the USA and other third countries.

This allows the behaviour of site visitors to be tracked after they have been redirected to the provider's website by clicking on a Facebook ad. This allows the effectiveness of Facebook ads to be evaluated for statistical and market research purposes and future advertising measures to be optimised.

The data collected is anonymous for us as the operator of this website; we cannot draw any conclusions about the identity of the users. However, the data is stored and processed by Facebook so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes in accordance with the Facebook Data Usage Policy. This enables Facebook to place adverts on Facebook pages and outside of Facebook. This use of the data cannot be influenced by us as the site operator.

To do this, we have set up ‘Advanced Match’ (Advanced Conversions). ‘Advanced Match’ is a feature that can be used to improve the accuracy of conversion tracking while protecting user privacy by supplementing existing conversion tags with hashed first-party conversion data from the website. Hashing the first-party data before sending it to Meta ensures data protection, as personal information (in this case: email address) is converted into a hashed / pseudonymised (SHA256) string.

The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR. Consent can be revoked at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission.

You can find details here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-.facebook.com/help/566994660333381.

Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its transfer to Facebook. The processing carried out by Facebook after forwarding is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in an agreement on joint processing. You can find the wording of the agreement at https://www.facebook.com/legal/controller_addendum.

According to this agreement, we are responsible for providing the data protection information when using the Facebook tool and for the secure implementation of the tool on our website in accordance with data protection law. Facebook is responsible for the data security of Facebook products. You can assert data subject rights (e.g. requests for information) regarding the data processed by Facebook directly with Facebook. If you assert your data subject rights with us, we are obliged to forward them to Facebook.

You can find further information on protecting your privacy in Facebook's data protection information: https://de-de.facebook.com/about/privacy/.

You can also deactivate the remarketing function "Custom Audiences" in the settings for Ads settings at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen.

You must be logged in to Facebook to do this.

Meta Custom Audiences

We use Meta Custom Audiences. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.

When you visit or use our websites and apps, make use of our free or paid offers, transmit data to us or interact with our company's Facebook content, we collect your personal data. If you give us permission to use Facebook Custom Audiences, we will transfer this data to Facebook, which Facebook can use to display suitable advertising to you. Furthermore, your data can be used to define target groups (lookalike audiences).

Facebook processes this data as our processor. Details can be found in the Facebook user agreement: https://www.facebook.com/legal/terms/customaudience.

The use of this service is based on your consent according to Art. 6 (1) a GDPR and Art. 25 TDDDG. The consent can be revoked at any time.

Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission.

Details can be found here: https://www.facebook.com/legal/terms/customaudience and https://www.facebook.com/legal/terms/dataprocessing. Furthermore, Facebook is certified according to the Data Privacy Framework.

Adform

This website uses the online marketing tool Adform from Adform A/S Denmark. Adform uses cookies to display adverts that are relevant to users, to improve campaign performance reports or to prevent users from seeing the same adverts more than once. Adform uses a cookie ID to record which ads are displayed in which browser and can thus prevent them from being displayed more than once. In addition, Adform can use cookie IDs to record conversions that are related to ad requests. This is the case, for example, when a user sees an Adform advert and later visits the advertiser's website with the same browser and makes a purchase there. Adform cookies do not contain any personal information such as email addresses, names or addresses.

Due to the marketing tools used, your browser automatically establishes a direct connection with the Adform server. By integrating the Adform cookie, Adform receives the information that you have accessed the relevant part of our website or clicked on one of our adverts.

In addition, the Adform cookies used enable us to understand whether you perform certain actions on our website after you have accessed or clicked on one of our display/video adverts on another platform via Adform (conversion tracking). Adform uses this cookie to understand the content you have interacted with on our websites in order to be able to send you targeted adverts later.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. This can be revoked at any time.

Adition

We use technologies from ADITION technologies AG (Germany) on our website to display interest-based advertising. Cookies are stored in the user's browser, allowing us to place adverts relevant to the user on other websites in the provider's advertising network (retargeting). Cookie IDs are used to record which adverts are displayed in which browser. This prevents the same campaign from being displayed multiple times. In addition, cookie IDs can be used to record conversions, i.e. whether a user sees an advert and later visits the advertiser's website and interacts with it. The data collected is statistically analysed in order to optimise the performance of the media campaigns. All usage data collected is stored using a pseudonym. The data collected is not used to personally identify visitors to our website and is not merged with personal data about the bearer of the pseudonym. Further information on data protection at ADITION can be found in ADITION's data protection information at www.adition.com/datenschutz-plattform/.

Further information on these processing activities, the technologies used, stored data and the storage period can be found in the cookie settings.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

AppNexus

In some areas of our website, we use AppNexus, a service for the display of usage-based advertising from AppNexus Inc, 28 W. 23rd Street New York, New York, 10010, USA. Among other things, AppNexus uses cookies that enable the use of the website to be analysed in order to display targeted, interest-based advertising. During use, your data, in particular your IP address and user activities, may be transmitted to an AppNexus server and stored there.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Further information on data protection can be found here in the AppNexus privacy policy at

https://www.appnexus.com/en/company/platform-privacy-policy-de

Targeting360

We use the Trageting360 service from targeting360 GmbH, Gredinger Str. 24a, 90453 Nuremberg, Germany on parts of our website.

When you visit our website, a cookie is set via the targeting360 ad server, which contains a reference to your surfing behaviour. The information collected is used to address the user in an individual and personalised manner via the website or via advertising placements on third-party websites that are linked to targeting360. You can prevent the setting of cookies by our website at any time by means of a corresponding setting of the Internet browser used and thus permanently object to the setting of cookies. Such a setting of the Internet browser used would also prevent targeting360 from setting a cookie on your information technology system. In addition, cookies already set by targeting360 can be deleted at any time via your internet browser or other software programmes.

The applicable data protection provisions of targeting360 may be retrieved under

https://targeting360.de/datenschutz/.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Yieldlab

On our website we use a web tracking service of the company Yieldlab AG, Colonnaden 41 , 20354 Hamburg, DE (hereinafter: Yieldlab). As part of web tracking, Yieldlab uses cookies that are stored on your computer and enable an analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis on the basis of Yieldlab's tracking service in order to constantly optimise our website and make it more accessible. When you use our website, data, in particular your IP address and your user activities, are transmitted to Yieldlab servers and processed and stored within the European Union. The data is deleted as soon as the purpose for which it was collected has been fulfilled. Further information on the handling of the transferred data can be found in Yieldlab's privacy policy:

http://www.yieldlab.de/meta-navigation/datenschutz/.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Adcanced store

We use various technologies from advanced store GmbH, Stefan-Heym-Platz 1, 10367 Berlin, Germany for the optimised display of relevant advertising material.

These technologies are used to collect technical information and data about the surfing behaviour of visitors to this website. This is done using cookies (small text files) or so-called LocalStorage (browser-based storage method), which are stored on your computer.

With the help of an analysis of surfing behaviour based on a special algorithm, advanced store can recommend products and offers on this and other websites that are specifically relevant, i.e. in line with your interests, by means of advertising banners. The use of the technologies employed serves solely to optimise the recommended advertising content; the website user is not personally identified.

advanced store has committed itself to the European industry standard for online behavioural advertising of the EDAA - further information on this and preference management can be found here: https://www.youronlinechoices.com/de/.

If you wish to object to the use of cookies or LocalStorage and the corresponding analysis of your surfing behaviour, you can do so here. You can find the provider's privacy policy here: https://www.advanced-store.com/en/data-privacy/.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

OpenX

Our website contains tracking technology from OpenX Technologies Inc ("OpenX", address for data protection issues: OpenX Technologies, Inc, Attention: Legal Department, 888 East Walnut Street, 2nd Fl, 91101 Pasadena/CA, United States). This may include cookies. A cookie is a small text file that is stored on your computer as soon as you visit a website.

If you visit the website again, the cookie indicates that it is a repeat visit. The cookie only contains a unique, automatically generated sequence of letters/numbers. The cookie does not contain any personal data. Cookies from a specific website/domain can only be read by pages of the same website/domain. A cookie is therefore not suitable for identifying you on third-party websites. OpenX collects and stores usage data in pseudonymised profiles for the purpose of web analysis or to enable interest-based advertising.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Rubicon Project

We use the Rubicon Project service provided by Rubicon Project Ltd, Walmar House, 5th Floor, 296 Regent St., London, W1B 3HR United Kingdom ("Rubicon"). Rubicon uses cookies. This involves processing anonymised data about the IP address, location and advertisements clicked on in order to optimise the advertisements on websites that participate in the advertising network.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

AWIN

We use components of the AWIN company on our website. The operating company of AWIN is AWIN AG, Eichhornstraße 3, 10785 Berlin, Germany.

AWIN is a German affiliate network and serves as an interface between merchants (merchants) and sales partners (affiliates).

Affiliate marketing is an Internet-supported form of distribution that enables commercial operators of websites, known as merchants or advertisers, to display adverts, which are usually remunerated via click or sale commissions, on third-party websites, i.e. with sales partners, also known as affiliates or publishers. The merchant provides an advertising medium via the affiliate network, i.e. an advertising banner or other suitable means of internet advertising, which is subsequently integrated by an affiliate on their own website or advertised via other channels, such as keyword advertising or email marketing.

AWIN places a cookie on the data subject's IT system. What cookies are has already been explained above. AWIN's tracking cookie does not store any personal data. Only the identification number of the affiliate, i.e. the partner referring the potential customer, as well as the order number of the visitor to a website and the advertising material clicked on are stored. The purpose of storing this data is to process commission payments between a merchant and the affiliate, which are processed via the affiliate network, i.e. AWIN.

The applicable data protection provisions of AWIN can be found at

https://www.awin.com/gb/privacy.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

We also use the service's customer match feature to create custom audiences from our customer data, which allows us to reach potential and existing customers with personalised advertising within the advertising network.

BidSwitch

Our website uses the technology of the provider BidSwitch GmbH (Bahnhofstrasse 28, Postfach 7563, 6302, Zug, Switzerland, "BidSwitch").

The use of BidSwitch technology makes it possible to recommend content that matches your personal interests and thus to personalise our offer for you. BidSwitch uses cookies to determine which websites you visit frequently and how you navigate our website. For this purpose, device-related data and log data are collected and usage profiles are generated using pseudonyms. These usage profiles are not merged with data about the bearer of the pseudonym and do not allow any conclusions to be drawn about your personal data. Your IP address, for example, is transmitted to BidSwitch in abbreviated form. You can find more information about BidSwitch at www.bidswitch.com/privacy-policy/.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Casale Media

A web service of the company Casale Media Inc, 74 Wingold Avenue, M6B1P5 Toronto (hereinafter: Casale Media) is loaded on our website. We use this data to ensure the full functionality of our website. In this context, your browser may transmit personal data to Casale Media.

The data will be deleted as soon as the purpose for which it was collected has been fulfilled. Further information on the handling of the transferred data can be found in Casale Media's privacy policy: http://casalemedia.com/.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Adobe Marketing Cloud

We use the Adobe Marketing Cloud ("Omniture"). This service is operated by Adobe Systems Software Ireland Limited, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Republic of Ireland. The Adobe Marketing Cloud enables analyses of visitor flows on websites. The analyses allow an immediate analysis of visitor flows. User behaviour is presented in a way that gives Aon an overview of the online activities of users of Aon websites. For this purpose, the data is displayed in interactive dashboards and converted into reports. This enables us to obtain information in real time and recognise any problems that arise more quickly. Data protection compliance always takes centre stage. The data is not collected in a personalised manner and is only used to create anonymised usage profiles to optimise and improve our websites.

The functionality of the Adobe Marketing Cloud requires the use of cookies. All information on the use of cookies can be found above in this privacy policy. Aon has made server settings to ensure that the information transmitted to Adobe is anonymised before geolocalisation. The anonymisation is implemented by replacing the last part of the IP address. Aon has also made settings to anonymise users' IP addresses independently of each other before processing for geolocalisation and reach measurement.

Adobe will use the transmitted information to evaluate the user behaviour of the anonymised users. Adobe will also use the anonymised data to create reports on user behaviour for us.

For more information about Adobe and the data collected and processed with the Adobe Marketing Cloud, please refer to Adobe's privacy policy: https://www.adobe.com/uk/privacy.html.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

PubMatic

In some areas of our websites, we use PubMatic, a service for displaying usage-based advertising. The provider is PubMatic Inc, 305 Main Street, First Floor, Redwood City, CA 9406, USA. PubMatic uses technologies to deliver adverts that are relevant to you.

Further information on data protection can be found here in PubMatic's privacy policy at https://pubmatic.com/legal/privacy-policy/.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Smart Adservice

We use Smart, a service provided by Smart AdServer GmbH, Mehringdamm 33, 10961 Berlin, Germany. Smart serves us as an ad server and integrated SSP for the display of interest-based or location-based advertising and the creation of aggregated statistics (e.g. to understand the effectiveness of an online advertising campaign).

IP address, cookie information (e.g. browser ID), technical information about the device (e.g. browser and operating system), information about the geographical location of the device, pseudonymous ID of the target group segmentation, information about other identifiers assigned to the device (IDFA, AAID), information about the user's activity on the device, including websites visited or used and mobile apps are processed.

Further information can be found at:

https://smartadserver.com/end-user-privacy-policy/

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

MediaMath

We use MediaMath Analytics & Insights, a web analytics service provided by MediaMath, Inc ("MediaMath"). MediaMath uses cookies, which are stored on your end device and enable your use of the website to be analysed. The data stored in these cookies may include, for example, the browser type, operating system, browser language, IP address and Internet provider.

MediaMath processes the data associated with your device into a pseudonym, a so-called "MediaMath ID". This unique MediaMath ID may then be stored in a cookie on your device and helps to provide you with more relevant adverts. The MediaMath ID and other information collected via the platform can also help us to measure your activity on our website and thus determine the effectiveness of the adverts provided via the platform. This allows us to better fulfil your needs. It also allows us to show you adverts for the types of products you may be interested in.

MediaMath may transfer this information to third parties where required to do so by law, or where such third parties process the information on MediaMath's behalf. For more information about how MediaMath uses your data and to opt out of MediaMath's use of cookies, please see MediaMath's privacy policy at:

http://www.mediamath.com/de/datenschutzrichtlinien/.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Teads

This website uses the Teads Retargeting Pixel from Teads SA ("TEADS", 5, rue de la Boucherie, L-1247 Luxembourg). This technology makes it possible to use TEADS advertising spaces on our partners' websites to target internet users who are interested in our content with adverts. To do this, the pixel records which unique user ID (UUID) has interacted (converted) on the pages on which the pixel is installed. If no UUID is recorded, no information is collected and no adverts are displayed.

In the case of TEADS services, the transmission of data to the USA cannot be ruled out. Further information on data protection at TEADS can be found in the TEADS privacy policy at

https://www.teads.com/privacy-policy/.

Standard contractual clauses in accordance with Art. 46 GDPR have been concluded with TEADS as suitable guarantees. Further information on this can be found here:

https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_de

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Admixer

On our website, we use the Admixer service provided by Admixer Limited, Suite 319-3, 32 Threadneedle Street, EC2R 8AY London, United Kingdom, website: https://admixer.net/. Processing also takes place in a third country outside the EU. There is an adequacy decision by the Commission for this third country. On the website of the EU Commission (Link: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_de) you will find a current list of all adequacy decisions.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

RhythmOne

We use the RhythmOne service provided by RhythmOne, 20 Garrick Street, WC2E 9BT London, United Kingdom, on our website. The processing also takes place in a third country outside the EU. An adequacy decision by the Commission exists for this third country.

The legal basis for the transfer of personal data is your consent in accordance with Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

The service is a plugin that we need in order to be able to show you all the content on our website. The service may also be used for tracking and/or advertising integration.

Further information on the handling of the transferred data can be found in the provider's privacy policy at

https://www.rhythmone.com/privacy-policy.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Unruly

The provider of Unruly is Unruly Media GmbH Großer Burstah 36-38 D-20457 Hamburg, ("Unruly") is a processor and purchases display advertising space. Delivery takes place via our own ad server. Information on data protection can be found here https://unruly.co/privacy/.If you do not want Unruly to continue to collect and process data, please click on the following link

https://video.unrulymedia.com/rtbprivacypolicy/index.html.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

AdYouLike

The provider of AdYouLike is AdYouLike, S. A, 38 Rue Boissiere, 75116 Paris. AdYouLike uses technologies to control and optimise the display of video advertisements for the user. Link to data protection information:

https://www.adyoulike.com/privacy_policy.php

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Twiago

Twiago is used by the digital advertising marketer Business Advertising GmbH. The provider of Twiago is twiago GmbH, Gustav-Heinemann-Ufer 72b, 50968 Cologne, Germany. Twiago uses technologies to control and optimise the display of advertising material for the user. Link to data protection information: https://www.twiago.com/datenschutz/

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

KUPONA

The use of KUPONA enables us to recognise visitors to our website and to present advertising material tailored to their interests. The advertising material may also relate to products and services that users have already viewed on our website. For this purpose, the interaction of users on one of our websites is analysed, e.g. which offers users are interested in, in order to be able to display targeted advertising to users on other websites even after they have visited our website. For this purpose, KUPONA uses tracking technologies such as cookies and so-called tracking pixels to collect information generated by the user's end device about interactions with our website and our advertising media (e.g. access to a specific website or click on an advertising medium) as well as access data, in particular IP address, browser information, the previously visited website and the date and time of the server request for the purpose of analysing user behaviour across end devices, displaying and measuring individualised advertising media to address our users again. For these purposes, it can also be determined whether different end devices belong to you or your household. We use this data in the display of individualised advertising material to retarget our users.

Your data will be transmitted to the NEORY ad server (NEORY GmbH, Brandschatstraße 2, 44149 Dortmund, Germany) for this purpose. While loading a website on which individualised advertising material is to be displayed, your browser sends a request to the NEORY ad server via which the individualised advertising is placed in real time. The ad server is used for the purpose of central planning and control of the advertising content, targeted delivery of advertisements and optimisation of the advertising space, as well as for reporting on the success of the placement of the advertising material.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

GPOne

Through our marketing service provider tectumedia GmbH (Eichhornstrasse 3, 10785 Berlin), we use a pixel from GP-One. GPOne uses its own ad serving system to measure and optimise the campaign figures. To control and optimise the campaigns, GPOne provides pixels to measure the change from a website visitor to a customer (the conversions) on the GALERIA website. The cookies are used via a container implemented by Tectumedia. The following data is stored: geographical information, device-related information, log data such as IP addresses (unreadable, non-personalised) and unique user tracking. GP-One is provided by GP One GmbH, Zur Linspher 3, 35108 Allendorf (Eder), Germany. The service provider tectumedia and we only receive aggregated data.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal

Mediavine

The Website works with Mediavine to manage third-party interest-based advertising that appears on the Website. Mediavine delivers content and adverts when you visit the Website which may use first and third party cookies. You can find out more about cookies above.

Mediavine partners may also use this data to link to other end-user information that the partner has independently collected to deliver targeted advertising. Mediavine Partners may also separately collect data about End Users from other sources, such as advertising IDs or pixels, and link this data to data collected by Mediavine Publishers to deliver interest-based advertising across your entire online experience, including devices, browsers and apps. This data includes usage data, cookie information, device information, information about interactions between users and ads and websites, geolocation data, traffic data and information about a visitor's referral source to a particular website. Mediavine partners may also create unique IDs to create audience segments that are used to deliver targeted advertising.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Outbrain

We have integrated Outbrain on this website. The provider is Outbrain Inc, 39 West 13th Street, 3rd floor, New York, NY 10011, USA (hereinafter "Outbrain").

When you visit a website on which Outbrain is integrated, Outbrain creates a pseudonymised user profile (user ID) in which the content you have viewed or read is stored. You can then be recommended further interest-based content or shown adverts on our website or on other websites on which Outbrain is integrated. For this purpose, your device type, IP address, browser type, websites visited and articles read, time of access and device ID are stored and summarised in your user ID.

We also use the Outbrain Pixel. When you enter our website, we can use this pixel to determine whether you already have an Outbrain user ID. This allows advertisers from the Outbrain advertising network to measure the effectiveness of their campaigns.

Further information can be found in Outbrain's privacy policy at https://www.outbrain.com/legal/privacy#privacy-policy.

You can also find a list of all cookies used by Outbrain at the following link https://www.outbrain.com/privacy/cookies/.

If you would like to view or customise your Outbrain interest profile, click on the following link: https://my.outbrain.com/recommendations-settings/home.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

We also use the service's customer match feature to create custom audiences from our customer data, which allows us to reach potential and existing customers with personalised advertising within the advertising network.

Taboola

We use a cookie from Taboola Inc ("Taboola", Oneustonsq, 40 Melton Street, 13th Floor, London, NW1 2FD) on our website. Taboola enables us to recommend content that matches your personal interests and thus create a customised offer for you. Taboola uses cookies to determine which websites you visit frequently and how you move around our website. You can find more information about Taboola at https://www.taboola.com/privacy-policy.

We also use the service's customer match feature to create custom audiences from our customer data, which allows us to reach potential and existing customers with personalised advertising within the advertising network.

Adscale

On our website we use a web tracking service of the company Ströer SSP GmbH, St.-Martin-Straße 106 , 81669 Munich, EU (hereinafter: Adscale). As part of web tracking, Adscale uses cookies that are stored on your computer and enable an analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis on the basis of Adscale's tracking service in order to constantly optimise our website and make it more accessible. When you use our website, data, in particular your IP address and your user activities, are transmitted to Adscale servers and processed and stored within the European Union. The legal basis for data processing is Art. 6 para. 1 lit. a GDPR. The data will be deleted as soon as the purpose of its collection has been fulfilled. Further information on the handling of the transferred data can be found in Adscale's privacy policy:

https://www.stroeer.de/en/data-protection/

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Trade Desk

This website uses The Trade Desk, a targeted advertising service provided by our partner Trade Desk, Inc, 42 N. Chestnut Street, Ventura, CA 93001 ("Trade Desk").

We use Trade Desk to better target advertising to you and your interests. We use behaviour-based advertising for this purpose. You can find Trade Desk's privacy policy here:

https://www.thetradedesk.com/us/privacy

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

The Reach Group

Cookies are used on our website to enable the placement of retargeting campaigns by The Reach Group GmbH (Am Karlsbad 16, 10785 Berlin, Germany). The data stored within the cookie is only an encrypted, pseudonymised user ID. The ad serving technology used utilises a shortened and hashed IP address to evaluate the geographical region, access speed and Internet provider. In addition, the time of the visit, the IDs of the products that were viewed, searched for or purchased, the URLs of the pages viewed, possible search terms and/or the IDs of the categories accessed are stored in order to deliver more relevant advertising content. IP or browser data is stored exclusively in Germany and for the anonymised preparation of visitor statistics and allocation of transactions. It is not possible at any time to draw conclusions about specific persons, the exact address, location or other personal data. IP data is not explicitly passed on to third parties. All information also has an expiry date of a maximum of 90 days, after which your browser automatically deletes the stored data.

Further information on data protection at The Reach Group GmbH can be found at

https://trg.de/datenschutzerklarung/

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Cross Engage

We would like to show you individualised content based on previous and current use of this website in order to make our offer more interesting for you as a user, which is why we use CrossEngage, a service of CrossEngage GmbH, Bertha-Benz-Str.5, 10557 Berlin. By using CrossEngage, we can, for example, show you individualised content and offers. CrossEngage is a cross-channel marketing platform with the aim of enabling a personalised customer approach in real time across all channels.

If you have consented to the use of CrossEngage, user data from all relevant data sources will be consolidated and made available for the design and execution of effective campaigns. Among other things, your email address will be passed on to CrossEngage in order to send you emails based on your behaviour. In order to be able to design and display this content, various cookies are set when you use this website, some of which have an unlimited duration and some of which are deleted after 12 months. We transfer the data collected via the cookies to CrossEngage in pseudonymised form for analysis.

Further information can be found at https://www.crossengage.io/privacy-policy/.

The legal basis for further data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

5. customer account

Contractual partners can create an account within our online offering (e.g. customer or user account, "customer account" for short). If the registration of a customer account is required, contractual partners will be informed of this as well as of the information required for registration. Customer accounts are not public and cannot be indexed by search engines. As part of the registration process and subsequent logins and use of the customer account, we store the IP addresses of customers together with the access times in order to be able to prove registration and prevent any misuse of the customer account.

If customers have cancelled their customer account, the data relating to the customer account will be deleted, unless their retention is required for legal reasons. It is the customer's responsibility to back up their data when the customer account is cancelled. The legal basis for data processing is therefore Art. 6 para. 1 lit. b GDPR.

5.1 Shop and e-commerce

We process our customers' data to enable them to select, purchase or order the selected products, goods and associated services, as well as their payment and delivery or fulfilment. If necessary for the fulfilment of an order, we use service providers, in particular postal, forwarding and shipping companies, to carry out the delivery or fulfilment for our customers. We use the services of banks and payment service providers to process payment transactions. The required information is labelled as such in the order or comparable purchase process and includes the information required for delivery or provision and billing as well as contact information in order to be able to hold any consultations.

- Processed data types: Inventory data (e.g. names, addresses), Payment data (e.g. bank details, invoices, payment history), Contact data (e.g. e-mail, telephone numbers), Contract data (e.g. contract object, duration, customer category), Usage data (e.g. websites visited, interest in content, access times), Meta/communication data (e.g. device information, IP addresses).

- Data subjects: Interested parties, business and contractual partners, customers.

- Purposes of Processing: Provision of contractual services and customer support, Contact requests and communication, Office and organisational procedures, Managing and responding to enquiries, Security measures, Conversion tracking (Measurement of the effectiveness of marketing activities), Interest-based and behavioral marketing, Profiling (Creating user profiles).

- Legal bases: Contract fulfilment and pre-contractual enquiries (Art. 6 Para. 1 S. 1 lit. b. GDPR), Legal obligation (Art. 6 Para. 1 S. 1 lit. c. GDPR), Legitimate interests (Art. 6 Para. 1 S. 1 lit. f. GDPR).

5.2 Economic analyses and market research

For economic reasons and in order to be able to identify market trends, wishes of contractual partners and users, we analyse the data available to us on business transactions, contracts, enquiries, etc., whereby the group of data subjects may include contractual partners, interested parties, customers, visitors and users of our online offer.

The analyses are carried out for the purpose of business evaluations, marketing and market research (e.g. to determine customer groups with different characteristics). If available, we may take into account the profiles of registered users, including their details, e.g. on services used. The analyses are used solely by us and are not disclosed externally, unless they are anonymous analyses with summarised, i.e. anonymised values. Furthermore, we take the privacy of users into account and process the data for analysis purposes as pseudonymously as possible and, where feasible, anonymously (e.g. as summarised data).

5.3 Analytics Union for end customers

"As a participant in the analytics union, a co-operation of various companies engaged in distance selling, we process your data within the scope of our legitimate interest pursuant to Art. 6 para. 1 lit. f. GDPR for our own and third-party marketing activities. GDPR for our own and third-party marketing activities. Your data is initially analysed by selected and reliable service providers on a pseudonymised basis together with data from other participating companies in order to identify relevant marketing activities for you and to be able to generate any interested new customers. For further information, please visit info.analyticsunion.de or contact CUSTOMY GmbH & Co. KG, Klarissengasse 4, 48143 Münster. The involvement of trusted service providers and the use of special encryption procedures as well as the conclusion of a processing agreement between joint controllers (Art. 26 GDPR) ensure that the data protection requirements of the GDPR are met.

You can object to the use of your data for these purposes directly to us or more simply on the following website info.analyticsunion.de in accordance with Art. 21 GDPR. If you object, your name and address will continue to be stored in pseudonymised form by the selected service providers in order to protect your rights and ensure that you no longer receive unsolicited advertising or that your data is processed for these purposes in the future. If, in addition to your objection, you also expressly request the complete deletion of this pseudonymised data, it can no longer be ensured that you will be excluded from marketing activities in the future, as no corresponding protective comparison can then be made with your pseudonymised data record created for this purpose. You can assert all other data subject rights arising from the GDPR, in particular your rights to information, rectification, erasure and transfer, directly against us. We will then process your request with the assistance of our cooperation partners.

In accordance with Art. 11 para. 1 GDPR, the possibility of your identification on the basis of the data concerning you will only be maintained for as long as is necessary for the purpose of the respective data processing. Due to the complex encryption procedures, it is therefore possible that your data can no longer be linked to your identity. In this case, the rights of data subjects under Art. 15-20 GDPR can only be asserted if you provide additional information that enables us or our cooperation partners to clearly identify you."

5.4 Payment service providers

In the context of contractual and other legal relationships, due to legal obligations or otherwise on the basis of our legitimate interests, we offer the data subjects efficient and secure payment options and use other payment service providers in addition to banks and credit institutions (collectively "payment service providers").

The data processed by the payment service providers includes inventory data, such as the name and address, bank data, such as account numbers or credit card numbers, passwords, TANs and checksums, as well as contract, total and recipient-related information. The information is required to carry out the transactions. However, the data entered is only processed by the payment service providers and stored by them. This means that we do not receive any account or credit card-related information, but only information with confirmation or negative information about the payment. Under certain circumstances, the data may be transmitted by the payment service providers to credit agencies. The purpose of this transmission is to check identity and creditworthiness. Please refer to the payment service providers' terms and conditions and data protection information.

Payment transactions are subject to the terms and conditions and the data protection notices of the respective payment service providers, which can be accessed on the respective websites or transaction applications. We also refer to these for further information and the assertion of cancellation, information and other data subject rights.

We transmit personal data collected within the scope of this contractual relationship regarding the application and execution of this business relationship as well as data on non-contractual behavior to CRIF GmbH, Leopoldstraße 244, 80807 Munich. The legal basis for this transfer is Article 6(1) sentence 1(b) and (f) of the General Data Protection Regulation (GDPR). CRIF GmbH processes the data received and also uses it for the purpose of profiling (scoring) in order to provide its contractual partners in the European Economic Area and Switzerland and, if applicable, other third countries with information, inter alia, to assess the creditworthiness of natural persons. The transfer of personal data to third countries takes place in accordance with Art. 44 et seq. GDPR. Further information on the activities of CRIF GmbH can be found in its information sheet or online at www.crif.de/en/privacy.

5.5 Transport service provider

For the purpose of delivering ordered goods, we work together with transport companies and/or shipping partners to whom the following data is transmitted for the purpose of delivering the ordered goods or for the purpose of shipment notification: First name, surname, postal address and, if applicable, the e-mail address and, if applicable, the telephone number. The legal basis for processing is Art. 6(1)(b) GDPR.

5.6 Advertising and lettershop

You can object to the use of your personal data for advertising purposes at any time, either as a whole or for individual measures, without incurring any costs other than the transmission costs according to the basic tariffs.

Subject to the legal requirements of Section 7 (3) UWG, we are authorised to use the email address or your address that you provided when concluding the contract for direct advertising for our own similar goods or services. You will receive these product recommendations from us regardless of whether you have subscribed to a newsletter.

If you do not wish to receive such recommendations from us by email or post, you can object to the use of your address for this purpose at any time without incurring any costs other than the transmission costs according to the basic rates. A message in text form is sufficient for this. Of course, every e-mail always contains an unsubscribe link.

As part of the advertising processing of data for letters to customers by post, we also rent addresses to third parties as part of the lettershop procedure. The processing is based on Art. 6 I lit. f. GDPR in conjunction with Recital 47 GDPR. You can object to this processing at any time with effect for the future.

The lettershop procedure is used for rental and dispatch. Address rental using the lettershop procedure means that we pass on personal data to other companies that offer goods or services of interest to the customer. In the lettershop procedure, the address data selected for the respective advertising letter is not transmitted to the company that is then advertising for advertising purposes, but is given to a lettershop that combines the address data with the advertising material requested by the advertising company. After dispatch, the address data is deleted. Your data will only be processed by the advertising company when you react to the advertising, e.g. by responding to advertising offers and ordering from the advertising company.

5.7 Sovendus

Voucher offers from Sovendus GmbH: To select a voucher offer that is currently of interest to you, we transmit the hash value of your email address and your IP address to Sovendus GmbH, Hermann-Veit-Str. 6, 76135 Karlsruhe (Sovendus) in pseudonymised and encrypted form (Art. 6 (1) f GDPR). The pseudonymised hash value of the email address is used to take into account any objection to advertising by Sovendus (Art. 21 para. 3, Art. 6 para. 1 c GDPR). The IP address is used by Sovendus exclusively for data security purposes and is generally anonymised after seven days (Art. 6 (1) f GDPR). We also transmit pseudonymised order number, order value with currency, session ID, coupon code and timestamp to Sovendus for billing purposes (Art. 6 para. 1 f GDPR). If you are interested in a voucher offer from Sovendus, there is no advertising objection to your e-mail address and you click on the voucher banner displayed only in this case, we will send your title, name, postcode, country and your e-mail address to Sovendus in encrypted form to prepare the voucher (Art. 6 para. 1 b, f GDPR).

For further information on the processing of your data by Sovendus, please refer to the online data protection information at

https://online.sovendus.com/en/online-privacy-notice/.

5.8 New customer acquisition and existing customer acquisition

We enrich our customer data with information that we receive from selected companies for new customer acquisition and existing customer marketing. The information we receive includes characteristics of consumer behaviour, mail order information, information on the respective living situation and micro-geographical data. It comes, for example, from household surveys on consumption and lifestyle topics as well as from home evaluations. This information helps us to differentiate between active and inactive customers, to activate dormant customers, to find out how likely existing customers are to be interested in certain products and to strengthen customer relationships.

In some cases, we also receive addresses from these companies so that we can approach new customers who match our customer profile.

In this case, you will find the specific source on the advertising medium. The legal basis for the aforementioned data processing is our legitimate interest pursuant to Art. 6 para. 1 f) GDPR in expanding your customer profile and providing you with more targeted advertising. You can object to this data processing at any time.

We would like to point out that in exceptional cases, advertising material may still be sent even after your objection has been received. This is for technical reasons and does not mean that we will not implement your objection.

6. Online presence on social media

If you have given your consent to the respective social media operator in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR, your data will be automatically collected and stored for market research and advertising purposes when you visit our online presences on our social media channels, from which user profiles are created using pseudonyms. These can be used, for example, to place adverts within and outside the platforms that presumably correspond to your interests. Cookies are generally used for this purpose. For detailed information on the processing and use of the data by the respective social media operator as well as a contact option and your rights and setting options for protecting your privacy, please refer to the respective linked data protection notices of the providers on their websites. If you still need help in this regard, you can contact us.

Plugins from Instagram, Facebook and LinkedIn

Social buttons from social networks are used on our website. These are only integrated into the page as HTML links so that no connection is established with the servers of the respective provider when our website is accessed. If you click on one of the buttons, the website of the respective social network opens in a new window of your browser. There you can click on the Like or Share button, for example.

7. Security

We have taken technical and administrative security precautions to protect your personal data against loss, destruction, manipulation and unauthorised access. All our employees and service providers working for us are obliged to comply with the applicable data protection laws.

Whenever we collect and process personal data, it is encrypted before it is transferred. This means that your data cannot be misused by third parties. Our security precautions are subject to a continuous improvement process and our data protection declarations are constantly being revised. Please ensure that you have the latest version.

8. What data protection rights do I have?

You have the right to information, correction, deletion or restriction of the processing of your stored data, a right to object to the processing as well as a right to data portability and to lodge a complaint in accordance with the requirements of data protection law.

Right to information:

You can request information from us as to whether and to what extent we process your data.

Right to rectification:

If we process your data that is incomplete or incorrect, you can request that we correct or complete it at any time.

Right to erasure:

You can demand that we erase your data if we process it unlawfully or if the processing disproportionately interferes with your legitimate protection interests. Please note that there may be reasons that prevent immediate erasure, e.g. in the case of statutory retention obligations.

Irrespective of the exercise of your right to erasure, we will erase your data immediately and completely, provided that there are no legal or statutory retention obligations to the contrary.

Right to restriction of processing:

You can demand that we restrict the processing of your data if

- you contest the accuracy of the data, for a period enabling us to verify the accuracy of the data

- the processing of the data is unlawful, but you oppose the erasure of the data and request the restriction of its use instead

- we no longer need the data for the intended purpose, but you still need this data for the assertion or defence of legal claims, or

- you have objected to the processing of the data.

Right to data portability:

You can request that we provide you with the data you have provided to us in a structured, commonly used and machine-readable format and that you can transmit this data to another controller without hindrance from us, provided that

- we process this data on the basis of your revocable consent or for the fulfilment of a contract between us, and

- this processing is carried out by automated means.

If technically feasible, you can request that we transfer your data directly to another controller.

Right to object:

If we process your data on the basis of a legitimate interest, you can object to this data processing at any time; this would also apply to profiling based on these provisions. We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or the processing serves the establishment, exercise or defence of legal claims. You can object to the processing of your data for the purpose of direct advertising at any time without giving reasons.

Right to lodge a complaint:

If you are of the opinion that we are violating German or European data protection law when processing your data, please contact us so that we can clarify any questions. Of course, you also have the right to contact the supervisory authority responsible for you, the respective state office for data protection supervision.

If you wish to assert one of these rights against us, please contact our data protection officer. In case of doubt, we may request additional information to confirm your identity.

Am I obliged to provide data?

The processing of your data is necessary for the conclusion or fulfilment of the contract you have entered into with us. If you do not provide us with this data, we will generally have to refuse to conclude the contract or will no longer be able to fulfil an existing contract and will therefore have to terminate it. However, you are not obliged to give your consent to data processing with regard to data that is not relevant or legally required for the fulfilment of the contract.

9 Changes to this privacy policy

We reserve the right to amend our privacy policy should this be necessary due to new technologies. Please ensure that you have the latest version. If fundamental changes are made to this privacy policy, we will announce these on our website.