Privacy policy

1) Introduction and Contact Details of the Controller


**1.1** We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data is any data that can personally identify you.

**1.2** The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Vincenzo Allocca, Breslauer Str. 8, 41460 Neuss, Germany, Tel.: +4915750644740, Email: info@vincenzoallocca.de. The controller for the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

**2) Data Collection When Visiting Our Website**

**2.1** When using our website purely for informational purposes, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files"). When you visit our website, we collect the following data that is technically necessary for us to display the website to you:

- Our visited website
- Date and time of access
- Amount of data sent in bytes
- Source/reference from which you reached the page
- Used browser
- Used operating system
- Used IP address (possibly in anonymized form)

The processing is carried out in accordance with Art. 6(1)(f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data is not shared or used in any other way. However, we reserve the right to check the server log files retrospectively if there are concrete indications of illegal use.

**2.2** This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller). You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser line.

**3) Hosting & Content Delivery Network**

**3.1 Shopify**

For hosting our website and displaying the site content, we use the system of the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify").

Data is also transmitted to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada.

All data collected on our website is processed on the provider's servers. We have concluded a data processing agreement with the provider to ensure the protection of our website visitors' data and to prohibit unauthorized sharing with third parties.

When data is transferred to Canada, an adequate level of data protection is guaranteed by an adequacy decision of the European Commission.

**3.2 Cloudflare**

We use a Content Delivery Network from the following provider: Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA.

This service allows us to deliver large media files such as graphics, content, or scripts more quickly via a network of regionally distributed servers. Processing is carried out to safeguard our legitimate interest in improving the stability and functionality of our website in accordance with Art. 6(1)(f) GDPR. We have concluded a data processing agreement with the provider to ensure the protection of our website visitors' data and to prohibit unauthorized sharing with third parties.

For data transfers to the USA, the provider has adhered to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on an adequacy decision by the European Commission.

**4) Cookies**

To make visiting our website attractive and to enable the use of certain functions, we use cookies, which are small text files that are stored on your device. Some of these cookies are automatically deleted after the browser is closed (so-called "session cookies"), while others remain on your device longer and enable the storage of page settings (so-called "persistent cookies"). In the latter case, you can see the storage duration in the cookie settings of your web browser.

If personal data is processed by individual cookies we use, the processing is carried out in accordance with Art. 6(1)(b) GDPR for the execution of the contract, in accordance with Art. 6(1)(a) GDPR in the case of consent given, or in accordance with Art. 6(1)(f) GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit.

You can set your browser to inform you about the setting of cookies and decide individually about their acceptance or exclude the acceptance of cookies for certain cases or in general.

Please note that the functionality of our website may be limited if cookies are not accepted.

**5) Contacting Us**

When contacting us (e.g., via contact form or email), personal data is processed solely for the purpose of handling and responding to your request and only to the extent necessary for this purpose.

The legal basis for processing these data is our legitimate interest in responding to your request in accordance with Art. 6(1)(f) GDPR. If your contact aims at a contract, the additional legal basis for processing is Art. 6(1)(b) GDPR. Your data will be deleted when it can be inferred from the circumstances that the matter in question has been conclusively clarified and provided there are no statutory retention obligations to the contrary.

**6) Data Processing When Opening a Customer Account**

In accordance with Art. 6(1)(b) GDPR, personal data will continue to be collected and processed to the extent necessary when you provide it to us when opening a customer account. The data required for account opening can be found in the input form on our website.

You can delete your customer account at any time, which can be done by sending a message to the above-mentioned address of the controller. After deleting your customer account, your data will be deleted, provided that all contracts concluded through it have been fully processed, there are no statutory retention obligations to the contrary, and we have no legitimate interest in further storage.

**7) Use of Customer Data for Direct Advertising**

Subscription to our Email Newsletter

If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information required for sending the newsletter is your email address. The provision of further data is voluntary and is used to address you personally. We use the so-called double opt-in procedure for sending the newsletter, which ensures that you only receive newsletters if you have expressly confirmed your consent to receive the newsletter by clicking on a verification link sent to the specified email address.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6(1)(a) GDPR. When you register for the newsletter, we store your IP address entered by your Internet service provider (ISP) as well as the date and time of registration to be able to trace any possible misuse of your email address at a later date. The data collected by us when registering for the newsletter will be used exclusively for the purpose of addressing you in an advertising manner.

You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending a corresponding message to the controller mentioned at the beginning. After unsubscribing, your email address will be immediately deleted from our newsletter distribution list, provided you have not expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration.

**8) Data Processing for Order Handling**

**8.1** To the extent necessary for contract execution for delivery and payment purposes, the personal data collected by us will be passed on to the contracted transport company and the contracted credit institution in accordance with Art. 6(1)(b) GDPR.

If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we will process the contact details (name, address, email address) provided by you when placing the order to inform you about upcoming updates within the legally stipulated period via suitable communication channels (e.g., post or email) in accordance with our legal information obligations under Art. 6(1)(c) GDPR. Your contact details will be used strictly for notifications about updates owed by us and will be processed only to the extent necessary for this purpose.

To handle your order, we also cooperate with the following service provider(s), who wholly or partly support us in executing concluded contracts. Certain personal data will be transferred to these service providers in accordance with the following information.

**8.2 Transfer of Personal Data to Shipping Service Providers**

- Deutsche Post

We use the following provider for transport services: Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany.

We will forward your email address and/or telephone number to the provider before the delivery of the goods in accordance with Art. 6(1)(a) GDPR for the purpose of coordinating a delivery date or delivery notification, provided you have given your explicit consent during the order process. Otherwise, we only forward the name of the recipient and the delivery address to the provider for the purpose of delivery in accordance with Art. 6(1)(b) GDPR. The forwarding is only to the extent necessary for the delivery of the goods. In this case, it is not possible to coordinate the delivery date with the provider or receive a delivery notification.

The consent can be revoked at any time with effect for the future against the above-mentioned controller or against the provider.

- DHL

We use the following provider for transport services: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany.

We will forward your email address and/or telephone number to the provider before the delivery of the goods in accordance with Art. 6(1)(a)

 GDPR for the purpose of coordinating a delivery date or delivery notification, provided you have given your explicit consent during the order process. Otherwise, we only forward the name of the recipient and the delivery address to the provider for the purpose of delivery in accordance with Art. 6(1)(b) GDPR. The forwarding is only to the extent necessary for the delivery of the goods. In this case, it is not possible to coordinate the delivery date with the provider or receive a delivery notification.

The consent can be revoked at any time with effect for the future against the above-mentioned controller or against the provider.

- DHL Express

We use the following provider for transport services: DHL Express Germany GmbH, Heinrich-Brüning-Str. 5, 53113 Bonn, Germany.

We will forward your email address and/or telephone number to the provider before the delivery of the goods in accordance with Art. 6(1)(a) GDPR for the purpose of coordinating a delivery date or delivery notification, provided you have given your explicit consent during the order process. Otherwise, we only forward the name of the recipient and the delivery address to the provider for the purpose of delivery in accordance with Art. 6(1)(b) GDPR. The forwarding is only to the extent necessary for the delivery of the goods. In this case, it is not possible to coordinate the delivery date with the provider or receive a delivery notification.

The consent can be revoked at any time with effect for the future against the above-mentioned controller or against the provider.

- UPS

We use the following provider for transport services: United Parcel Service Deutschland Inc. & Co. OHG, Görlitzer Straße 1, 41460 Neuss, Germany.

We will forward your email address and/or telephone number to the provider before the delivery of the goods in accordance with Art. 6(1)(a) GDPR for the purpose of coordinating a delivery date or delivery notification, provided you have given your explicit consent during the order process. Otherwise, we only forward the name of the recipient and the delivery address to the provider for the purpose of delivery in accordance with Art. 6(1)(b) GDPR. The forwarding is only to the extent necessary for the delivery of the goods. In this case, it is not possible to coordinate the delivery date with the provider or receive a delivery notification.

The consent can be revoked at any time with effect for the future against the above-mentioned controller or against the provider.

**8.3 Use of Payment Service Providers (Payment Services)**

- Apple Pay

If you choose the "Apple Pay" payment method of Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, the payment will be processed via the "Apple Pay" function of your iOS, watchOS, or macOS operated device by charging a payment card stored in "Apple Pay." Apple Pay uses security features built into your device's hardware and software to protect your transactions. To authorize a payment, it is necessary to enter a previously set code and verify it using the "Face ID" or "Touch ID" function of your device.

For the purpose of payment processing, the information you provide during the ordering process, along with information about your order, is transmitted to Apple in encrypted form. Apple then re-encrypts this data with a developer-specific key before the data is transmitted to the payment service provider of the payment card stored in Apple Pay. This encryption ensures that only the website through which the purchase was made can access the payment data. Once the payment is made, Apple sends a device account number and a transaction-specific dynamic security code to the originating website to confirm the payment success.

If personal data is processed during the described transfers, the processing is carried out solely for the purpose of payment processing in accordance with Art. 6(1)(b) GDPR.

Apple stores anonymized transaction data, including the approximate purchase amount, approximate date and time, and indication of whether the transaction was successfully completed. Anonymization completely excludes personal reference. Apple uses the anonymized data to improve "Apple Pay" and other Apple products and services.

If you use Apple Pay on the iPhone or Apple Watch to complete a purchase you made through Safari on the Mac, the Mac and the authorization device communicate via an encrypted channel on Apple servers. Apple does not process or store any of this information in a format that can identify you personally. You can disable the ability to use Apple Pay on your Mac in your iPhone settings. Go to "Wallet & Apple Pay" and disable "Allow Payments on Mac."

Further information on data protection at Apple Pay can be found at the following Internet address: https://support.apple.com/en-us/HT203027

- Google Pay

If you choose the "Google Pay" payment method of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), the payment will be processed via the "Google Pay" application of your Android-operated mobile device (version at least Android 4.4 "KitKat") with an NFC function by charging a payment card stored in Google Pay or a verified payment system (e.g., PayPal). To authorize a payment over €25, the prior unlocking of your mobile device through the respective verification measure (e.g., face recognition, password, fingerprint, or pattern) is required.

For the purpose of payment processing, the information you provide during the ordering process, along with information about your order, is transmitted to Google. Google then transmits your payment information stored in Google Pay as a one-time transaction number to the originating website to verify the payment. This transaction number does not contain any real payment data of your stored payment methods in Google Pay but is created and transmitted as a one-time valid numerical token. For all transactions via Google Pay, Google only acts as an intermediary for processing the payment transaction. The transaction is carried out exclusively between the user and the originating website by charging the payment method stored in Google Pay.

If personal data is processed during the described transfers, the processing is carried out solely for the purpose of payment processing in accordance with Art. 6(1)(b) GDPR.

Google reserves the right to collect, store, and evaluate certain transaction-specific information for each transaction made via Google Pay. This includes the date, time, and amount of the transaction, merchant location and description, a description of the goods or services provided by the merchant, photos you attached to the transaction, the name and email address of the seller and buyer, or sender and recipient, the payment method used, your description of the reason for the transaction, and any associated offer.

According to Google, this processing is carried out solely in accordance with Art. 6(1)(f) GDPR based on Google's legitimate interest in proper billing, verification of transaction data, and optimization and maintenance of the functionality of the Google Pay service.

Google also reserves the right to merge the processed transaction data with other information collected and stored by Google when using other Google services.

The Google Pay Terms of Use can be found here:
https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=googlepaytos&ldl=en
Further information on data protection at Google Pay can be found at the following Internet address:
https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice&ldl=en

- Klarna

One or more online payment methods of the following provider are available on this website: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden.

When selecting a payment method from the provider where you pay in advance (e.g., credit card payment), your payment data provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order will be transmitted to the provider in accordance with Art. 6(1)(b) GDPR. The transfer of your data in this case is solely for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

When selecting a payment method where the provider makes an advance payment (e.g., invoice or installment purchase or direct debit), you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, possibly data on an alternative payment method) during the order process.

To protect our legitimate interest in determining the payment ability of our customers, this data will be transmitted to the provider for the purpose of a credit check in accordance with Art. 6(1)(f) GDPR. The provider checks, based on the personal data provided by you, as well as other data (such as shopping cart, invoice amount, order history, payment experiences), whether the payment method selected by you can be granted regarding payment and/or bad debt risks.

In the context of the credit check, identity and credit information from the following credit agencies may also be included in the decision according to Art. 6(1)(f) GDPR:

https://cdn.klarna.com/1.0/shared/content/legal/terms/0/en_de/credit_rating_agencies

The credit report can contain probability values (so-called score values). As far as score values are included in the result of the credit report, they have their basis in a scientifically recognized mathematical-statistical procedure. Among other data, but not exclusively, address data is included in the calculation of the score values.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider remains entitled to process your personal data if this is necessary for the contractual payment processing.

- PayPal

One or more online payment methods of the following provider are available on this website: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.

When selecting a payment

 method from the provider where you pay in advance, your payment data provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order will be transmitted to the provider in accordance with Art. 6(1)(b) GDPR. The transfer of your data in this case is solely for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

When selecting a payment method where we make an advance payment, you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, possibly data on an alternative payment method) during the order process.

To protect our legitimate interest in determining your payment ability, this data will be transmitted to the provider for the purpose of a credit check in accordance with Art. 6(1)(f) GDPR. The provider checks, based on the personal data provided by you, as well as other data (such as shopping cart, invoice amount, order history, payment experiences), whether the payment method selected by you can be granted regarding payment and/or bad debt risks.

The credit report can contain probability values (so-called score values). As far as score values are included in the result of the credit report, they have their basis in a scientifically recognized mathematical-statistical procedure. Among other data, but not exclusively, address data is included in the calculation of the score values.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider remains entitled to process your personal data if this is necessary for the contractual payment processing.

- PayPal Checkout

This website uses PayPal Checkout, an online payment system from PayPal, which consists of PayPal's own payment methods and local third-party payment methods.

When paying via PayPal, credit card via PayPal, direct debit via PayPal, or - if offered - "Pay Later" via PayPal, we will forward your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") within the framework of the payment processing. The forwarding takes place in accordance with Art. 6(1)(b) GDPR and only to the extent necessary for the payment processing.

PayPal reserves the right to carry out a credit check for the payment methods credit card via PayPal, direct debit via PayPal, or - if offered - "Pay Later" via PayPal. For this purpose, your payment data may be forwarded to credit agencies based on the legitimate interest of PayPal in determining your payment ability in accordance with Art. 6(1)(f) GDPR. The result of the credit check regarding the statistical probability of non-payment is used by PayPal for the purpose of deciding whether to provide the respective payment method. The credit report can contain probability values (so-called score values). As far as score values are included in the result of the credit report, they have their basis in a scientifically recognized mathematical-statistical procedure. Among other data, but not exclusively, address data is included in the calculation of the score values. You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal remains entitled to process your personal data if this is necessary for the contractual payment processing.

When selecting the PayPal payment method "purchase on account," your payment data will first be transmitted to PayPal for the purpose of preparing the payment, after which PayPal will forward it to Ratepay GmbH, Franklinstraße 28-29, 10587 Berlin ("Ratepay") for payment processing. The legal basis is each time Art. 6(1)(b) GDPR. In this case, RatePay conducts an identity and credit check in its own name to determine payment ability according to the already mentioned principle and forwards your payment data to credit agencies based on the legitimate interest in determining payment ability in accordance with Art. 6(1)(f) GDPR. A list of credit agencies that Ratepay can use can be found here: https://www.ratepay.com/legal-payment-creditagencies/

When using the payment method of a local third party, your payment data will first be transmitted to PayPal for the purpose of preparing the payment in accordance with Art. 6(1)(b) GDPR. Depending on your selection of an available local payment method, PayPal will then transmit your payment data to the corresponding provider for payment processing in accordance with Art. 6(1)(b) GDPR:

- Apple Pay (Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland)
- Google Pay (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland)
- Sofort (SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany)
- iDeal (Currence Holding BV, Beethovenstraat 300 Amsterdam, Netherlands)
- bancontact (Bancontact Payconiq Company, Rue d'Arlon 82, 1040 Brussels, Belgium)
- blik (Polski Standard Płatności sp. z o.o., ul. Czerniakowska 87A, 00-718 Warsaw, Poland)
- eps (PSA Payment Services Austria GmbH, Handelskai 92, Gate 2, 1200 Vienna, Austria)
- MyBank (PRETA S.A.S, 40 Rue de Courcelles, F-75008 Paris, France)
- Przelewy24 (PayPro SA, Kanclerska 15A, 60-326 Poznań, Poland)

Further data protection information can be found in PayPal's privacy policy: https://www.paypal.com/en/webapps/mpp/ua/privacy-full

- Shopify Payments

One or more online payment methods of the following provider are available on this website: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.

When selecting a payment method from the provider where you pay in advance (e.g., credit card payment), your payment data provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order will be transmitted to the provider in accordance with Art. 6(1)(b) GDPR. The transfer of your data in this case is solely for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

**9) Web Analysis Services**

**9.1 Google Analytics 4**

This website uses Google Analytics 4, a web analysis service from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables an analysis of your use of our website.

By default, Google Analytics 4 sets cookies when you visit the website, which are stored as small text files on your device and collect certain information. This includes your IP address, which Google truncates by the last digits to exclude direct personal reference.

The information is transmitted to Google's servers and further processed there. Transfers to Google LLC with its seat in the USA are also possible.

Google uses the collected information on our behalf to evaluate your use of the website, compile reports on website activity, and provide further services related to website and internet usage. The IP address transmitted by your browser within the scope of Google Analytics 4 is not merged with other data from Google. Data collected in the context of using Google Analytics 4 is stored for two months and then deleted.

All the described processing operations, particularly setting cookies on the used device, only occur if you have given us your explicit consent according to Art. 6(1)(a) GDPR. Without your consent, the use of Google Analytics 4 will be omitted during your visit. You can revoke your consent with effect for the future at any time. To exercise your revocation, please disable this service via the "Cookie-Consent-Tool" provided on the website.

We have concluded a data processing agreement with Google to ensure the protection of our website visitors' data and to prohibit unauthorized sharing with third parties.

Further legal information on Google Analytics 4 can be found at https://policies.google.com/privacy?hl=en and at https://policies.google.com/technologies/partner-sites

**Demographic Features**
Google Analytics 4 uses the special "demographic features" function and can create statistics about the age, gender, and interests of website visitors. This happens through the analysis of advertisements and third-party information. This way, target groups for marketing activities can be identified. However, the collected data cannot be assigned to a specific person and will be deleted after being stored for two months.

**Google Signals**
As an extension to Google Analytics 4, Google Signals can be used on this website to create cross-device reports. If you have personalized ads enabled and have linked your devices with your Google account, Google can analyze your usage behavior across devices, subject to your consent to use Google Analytics according to Art. 6(1)(a) GDPR, and create database models, including cross-device conversions. We do not receive personal data from Google, only statistics. If you want to stop the cross-device analysis, you can disable the "Personalized Ads" function in your Google account settings. Follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=en Further information on Google Signals can be found at the following link: https://support.google.com/analytics/answer/7532985?hl=en

**UserIDs**
As an extension to Google Analytics 4, the "UserIDs" function can be used on this website. If you have consented to use Google Analytics 4 according to Art. 6

(1)(a) GDPR, have set up an account on this website, and log in to this account on different devices, your activities, including conversions, can be analyzed across devices.

For data transfers to the USA, the provider has adhered to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on an adequacy decision by the European Commission.

**9.2 Google Tag Manager**

This website uses the "Google Tag Manager," a service of the following provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: "Google").

The Google Tag Manager provides a technical basis for bundling and calibrating various web applications, including tracking and analysis services, through a unified user interface. The Google Tag Manager itself does not store any information on user devices or read it out. It also does not conduct any independent data analyses. However, when the Google Tag Manager is called, your IP address is transmitted to Google and possibly stored there. Transfers to Google LLC. in the USA are also possible.

This processing will only take place if you have given us your explicit consent according to Art. 6(1)(a) GDPR. Without this consent, the use of Google Tag Manager will be omitted during your visit. You can revoke your consent at any time with effect for the future. To exercise your revocation, please disable this service via the "Cookie-Consent-Tool" provided on the website.

We have concluded a data processing agreement with the provider to ensure the protection of our website visitors' data and to prohibit unauthorized sharing with third parties.

For data transfers to the USA, the provider has adhered to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on an adequacy decision by the European Commission.

**10) Retargeting/Remarketing and Conversion Tracking**

**Meta Pixel**

Within our online offer, we use the "Meta Pixel" service of the following provider: Meta Platforms Ireland Limited, 4 Grand Canal Quare, Dublin 2, Ireland ("Meta").

When a user clicks on an ad placed by us on Facebook and/or Instagram, the URL of our linked page is extended by a parameter using "Meta Pixel." This URL parameter is then entered into the user's browser by a cookie set by our linked page after redirection.

This enables Meta to determine the visitors of our online offer as a target group for displaying ads (so-called "ads"). Accordingly, we use the service to show ads placed by us on Facebook and/or Instagram only to those users who have also shown an interest in our online offer or who exhibit certain characteristics (e.g., interests in certain topics or products based on the visited websites) that we transmit to Meta ("Custom Audiences").

On the other hand, "Meta Pixel" allows us to track whether users are redirected to our website after clicking on an ad and what actions they take there (so-called "conversion tracking").

The collected data is anonymous for us, so it does not provide any conclusions about the identity of the users. However, the data is stored and processed by Meta, enabling a connection to the respective user profile and Meta's use of the data for its own advertising purposes.

All the above-described processing operations, particularly setting cookies to read out information on the used device, are only carried out if you have given us your explicit consent according to Art. 6(1)(a) GDPR. You can revoke your consent at any time with effect for the future by disabling this service in the "Cookie-Consent-Tool" provided on the website.

We have concluded a data processing agreement with the provider to ensure the protection of our website visitors' data and to prohibit unauthorized sharing with third parties.

The information generated by Meta is usually transferred to a Meta server and stored there; this may also involve transmission to servers of Meta Platforms Inc. in the USA.

For data transfers to the USA, the provider has adhered to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on an adequacy decision by the European Commission.

**11) Tools and Miscellaneous**

**Cookie-Consent-Tool**

This website uses a so-called "Cookie-Consent-Tool" to obtain effective user consent for consent-based cookies and cookie-based applications. The "Cookie-Consent-Tool" is displayed to users as an interactive user interface when the page is accessed, where consents can be given by setting checkmarks for certain cookies and/or cookie-based applications. By using the tool, all consent-based cookies/services are only loaded if the respective user gives the corresponding consents by setting checkmarks. This ensures that such cookies are only set on the user's device if the respective consent is given.

The tool sets technically necessary cookies to save your cookie preferences. Personal user data is generally not processed.

In individual cases, if personal data (such as the IP address) is processed for storage, assignment, or logging of cookie settings, this processing is based on our legitimate interest in a lawful, user-specific, and user-friendly consent management for cookies according to Art. 6(1)(f) GDPR, and thus in the lawful design of our online presence.

Further legal basis for processing is also Art. 6(1)(c) GDPR. As controllers, we are legally obligated to make the use of technically unnecessary cookies dependent on the respective user consent.

If necessary, we have concluded a data processing agreement with the provider to ensure the protection of our website visitors' data and to prohibit unauthorized sharing with third parties.

Further information about the operator and the setting options of the Cookie-Consent-Tool can be found directly in the corresponding user interface on our website.

**12) Rights of the Data Subject**

**12.1** The applicable data protection law grants you the following rights of data subjects (information and intervention rights) towards the controller concerning the processing of your personal data, whereby reference is made to the cited legal basis for the respective exercise conditions:

- Right to information according to Art. 15 GDPR;
- Right to correction according to Art. 16 GDPR;
- Right to deletion according to Art. 17 GDPR;
- Right to restriction of processing according to Art. 18 GDPR;
- Right to notification according to Art. 19 GDPR;
- Right to data portability according to Art. 20 GDPR;
- Right to revoke granted consents according to Art. 7(3) GDPR;
- Right to complain according to Art. 77 GDPR.

**12.2 RIGHT TO OBJECT**

IF WE PROCESS YOUR PERSONAL DATA BASED ON OUR LEGITIMATE INTEREST IN THE CONTEXT OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION WITH EFFECT FOR THE FUTURE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE AFFECTED DATA. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN PROVE COMPELLING LEGITIMATE REASONS FOR PROCESSING THAT OUTWEIGH YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR IF THE PROCESSING SERVES THE ASSERTION, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.

IF YOUR PERSONAL DATA IS PROCESSED BY US FOR DIRECT ADVERTISING PURPOSES, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH ADVERTISING AT ANY TIME. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE AFFECTED DATA FOR DIRECT ADVERTISING PURPOSES.

**13) Duration of Storage of Personal Data**

The duration of the storage of personal data is determined based on the respective legal basis, the processing purpose, and – if relevant – additionally based on the respective statutory retention period (e.g., commercial and tax retention periods).

When processing personal data based on explicit consent according to Art. 6(1)(a) GDPR, the data concerned will be stored until you revoke your consent.

If there are statutory retention periods for data processed in the context of legal transactions or similar obligations based on Art. 6(1)(b) GDPR, this data will be routinely deleted after the expiration of the retention periods if it is no longer necessary for contract fulfillment or contract initiation and/or we have no legitimate interest in further storage.

When processing personal data based on Art. 6(1)(f) GDPR, this data will be stored until you exercise your right to object according to Art. 21(1) GDPR unless we can prove compelling legitimate reasons for processing that outweigh your interests, rights, and freedoms, or the processing serves the assertion, exercise, or defense of legal claims.

When processing personal data for direct advertising purposes based on Art. 6(1)(f) GDPR, this data will be stored until you exercise your right to object according to Art. 21(2) GDPR.

Unless otherwise specified in the other information of this declaration regarding specific processing situations, stored personal data will otherwise be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.