Data Protection Declaration
1) Information on the Collection of Personal Data and Contact Details of the Controller
1.1 We are pleased that you are visiting our website and thank you for your interest. On the following pages, we inform you about the handling of your personal data when using our website. Personal data is all data with which you can be personally identified.
1.2 The controller in charge of data processing on this website, within the meaning of the General Data Protection Regulation (GDPR), is Plant-for-the-Planet Foundation, Lindemannstr. 13, 82327, Germany, Phone.: +49 (0)8808 9345, Fax: +49 (0)8808 9346, e-mail: info@plant-for-the-planet.org. The controller in charge of the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
1.3 The controller has designated a data protection officer for this website. He can be reached as follows: ""Proliance GmbH, Dominik Fünkner", Address: Leopoldstr. 21, 80802 Munich. E-Mail: datenschutzbeauftragter@datenschutzexperte.de"
2) Data Collection When You Visit Our Website
2.1 When using our website for information only, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files"). When you visit our website, we collect the following data that is technically necessary for us to display the website to you:
- Our visited website
- Date and time at the moment of access
- Amount of data sent in bytes
- Source/reference from which you came to the page
- Browser used
- Operating system used
- IP address used (if applicable: in anonymized form)
Data processing is carried out in accordance with Art. 6 (1) point f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files subsequently, if there are any concrete indications of illegal use.
2.2 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the controller). You can recognize an encrypted connection by the character string https:// and the lock symbol in your browser line.
3) Hosting & Content Delivery Network
3.1 Amazon Web Services
For the hosting of our website and the display of the page content, we use the system of the following provider: Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA
All data collected on our website is processed on the provider's servers. We have concluded an order processing agreement with the provider, ensuring the protection of our site visitors' data and prohibiting unauthorised disclosure to third parties.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
3.2 DigitalOcean
For the hosting of our website and the display of the page content, we use the system of the following provider: DigitalOcean LLC, 101 Avenue of the Americas 10th Floor New York, NY 10013, USA
All data collected on our website is processed on the provider's servers. We have concluded an order processing agreement with the provider, ensuring the protection of our site visitors' data and prohibiting unauthorised disclosure to third parties.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
3.3 Microsoft Azure
For the hosting of our website and the display of the page content, we use the system of the following provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA
All data collected on our website is processed on the provider's servers. We have concluded an order processing agreement with the provider, ensuring the protection of our site visitors' data and prohibiting unauthorised disclosure to third parties.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
3.4 Vercel
For the hosting of our website and the display of the page content, we use the system of the following provider: Vercel Inc, 340 S Lemon Ave #4133, Walnut, CA 91789, USA
All data collected on our website is processed on the provider's servers. We have concluded an order processing agreement with the provider, ensuring the protection of our site visitors' data and prohibiting unauthorised disclosure to third parties.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
3.5 Cloudflare
We use a content delivery network offered by the following provider: Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA
This service enables us to deliver large media files such as graphics, page content or scripts faster via a network of regionally distributed servers. The processing is carried out to protect our legitimate interest in improving the stability and functionality of our website pursuant to Art. 6 (1) point f GDPR. We have concluded an order processing agreement with the provider, ensuring the protection of our site visitors' data and prohibiting unauthorised disclosure to third parties.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
4) Cookies
In order to make your visit to our website more attractive and to enable the use of certain functions, we use cookies, i.e. small text files that are stored on your end device. In some cases, these cookies are automatically deleted again after the browser is closed (so-called "session cookies"), in other cases, these cookies remain on your end device for longer and allow page settings to be saved (so-called "persistent cookies"). In the latter case, you can find the duration of the storage in the overview of the cookie settings of your web browser.
If personal data is also processed by individual cookies set by us, the processing is carried out either in accordance with Art. 6 (1) point b GDPR for the performance of the contract, in accordance with Art. 6 (1) point a GDPR in the case of consent given or in accordance with Art. 6 (1) point f GDPR to safeguard our legitimate interests in the best possible functionality of the website as well as a customer-friendly and effective design of the page visit.
You can set your browser in such a way that you are informed about the setting of cookies and you can decide individually about their acceptance or exclude the acceptance of cookies for certain cases or in general.
Please note that the functionality of our website may be limited if cookies are not accepted.
5) Contacting Us
When you contact us (e.g. via contact form or e-mail), personal data is collected. Which data is collected in the case of a contact form can be seen from the respective contact form. This data is stored and used exclusively for the purpose of responding to your request or for establishing contact and for the associated technical administration.
The legal basis for processing data is our legitimate interest in responding to your request in accordance with Art. 6 (1) point f GDPR. If your contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6 (1) point b GDPR. Your data will be deleted after final processing of your enquiry; this is the case if it can be inferred from the circumstances that the facts in question have been finally clarified, provided there are no legal storage obligations to the contrary.
6) Data Processing When Opening a Customer Account and for Contract Processing
Pursuant to Art. 6 (1) point b GDPR, personal data will continue to be collected and processed to the extent required in each case if you provide us with this data when opening a customer account. The data required for opening an account can be found in the input mask of the corresponding form on our website. Deletion of your customer account is possible at any time and can be done by sending a message to the above address of the person responsible. After deletion of your customer account, your data will be deleted, provided that all contracts concluded via it have been fully processed, no legal retention periods are opposed and no legitimate interest on our part in the continued storage exists.
7) Commentary Function
In the context of the comment function on this website, in addition to your comment, information on the time of the creation of the comment and the commentator name you have chosen will be stored and published on this website. Furthermore, your IP address will be logged and stored. This storage of the IP address is for security reasons and for the event that the data subject infringes the rights of third parties by posting a comment or posts illegal content. We need your e-mail address in order to contact you in case a third party claims that your published content is illegal.
The legal bases for storing your data is Art. 6 (1) point b and point f GDPR. We reserve the right to delete comments if they are claimed to be unlawful by third parties.
You as a user can subscribe to the follow-up comments. For this purpose, you will receive a confirmation e-mail so that it can be ensured that you are the owner of the e-mail address provided (double opt-in procedure). The legal basis for data processing in the case of comment subscriptions is Art. 6 (1) point a GDPR. You can unsubscribe from ongoing comment subscriptions at any time with effect for the future; for more information on the unsubscription option, please refer to the confirmation e-mail.
8) Use of Client Data for Direct Advertising
8.1 Subscribe to our e-mail newsletter
If you register for our e-mail newsletter, we will regularly send you information about our offers. The only mandatory data for sending the newsletter is your e-mail address. The provision of further data is voluntary and will be used to address you personally. We use the so-called double opt-in procedure for sending the newsletter. This means that we will only send you an e-mail newsletter once you have expressly confirmed that you consent to receiving newsletters. We will then send you a confirmation e-mail asking you to confirm that you wish to receive the newsletter in future by clicking on an appropriate link.
By activating the confirmation link, you give us your consent for the use of your personal data pursuant to Art. 6 (1) point a GDPR. When you register for the newsletter, we store your IP address entered by your Internet service provider (ISP) as well as the date and time of registration for the purpose of tracing any possible misuse of your e-mail address at a later date. The data collected by us when you register for the newsletter is used exclusively for the promotional purposes by way of the newsletter. You can unsubscribe from the newsletter at any time via the link provided for this purpose in the newsletter or by sending a corresponding message to the responsible person named at the beginning. After unsubscribing, your e-mail address will be deleted from our newsletter distribution list immediately, unless you have expressly consented to further use of your data, or we reserve the right to a more extensive use your data which is permitted by law and about which we inform you in this declaration.
8.2 Sending the newsletter to existing customers
If you have provided us with your e-mail address when purchasing products, we reserve the right to regularly send you offers for products similar to those already purchased by e-mail. Pursuant to Section 7 (3) German law against unfair competition, we do not need to obtain separate consent from you. In this respect, data processing is carried out solely on the basis of our legitimate interest in personalized direct advertising pursuant to Art. 6 (1) point f GDPR. If you have initially objected to the use of your e-mail address for this purpose, we will not send you an e-mail. You are entitled to object to the future use of your e-mail address for the aforementioned advertising purpose at any time by notifying the controller named at the beginning of this document. In this regard, you only have to pay the transmission costs according to the basic tariffs. Upon receipt of your objection, the use of your e-mail address for advertising purposes will cease immediately.
8.3 Advertising by post
Based on our legitimate interest in personalized direct mail, we reserve the right to store your first and last name, your postal address and - if we have received this additional information from you within the framework of the contractual relationship - your title, academic degree, year of birth and your professional, industry or business name in accordance with Art. 6 (1) point f GDPR and to use this data for sending interesting offers and information on our products by letter post.
You can object to the storage and use of your data for this purpose at any time by sending an appropriate message to the controller.
9) Data processing for the processing of donations
We generally process the following personal data for the processing of donations that you may send us: First name and surname, address, email address.
Your data will be stored by us together with details of the donation amount, donation frequency and donation purpose and kept for ten years.
Depending on the selected payment method, the above-mentioned data will also be forwarded to the payment service provider you have selected for the donation and processed there exclusively and only to the extent necessary to process your donation.
The above-mentioned processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR and serves exclusively to properly process your donation payment and to record it in the accounts. The storage for a period of 10 years is based on Art. 6 para. 1 lit. c GDPR in conjunction with Section 147 of the German Fiscal Code, according to which we are subject to a corresponding retention obligation regarding the business transaction.
Personalisation of tree certificates:
For selected projects, after making a donation, the donor has the option of dedicating the donation and having personalized certificates generated automatically by entering the first and last names of one or more persons named by the donor. These certificates certify the personal support of the respective project by the named person and can be downloaded by the donor via their user account or sent to the named person if an email and message is shared by the donor.
The collection, processing and storage of personal data for the personalisation of the certificates is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in the appropriate provision of information and symbolic rewarding of donations and in view of the donor's legitimate interest in having the financial support symbolically certified.
The data processed for personalisation is generally stored for as long as the donor's corresponding user account is maintained.
However, data subjects whose personal data is or was the subject of a certificate personalisation can object to the data processing at any time in accordance with Art. 21 GDPR. In the event of such an objection, the data will be deleted immediately, unless there are exceptional, legally recognised reasons for further storage.
10) Processing of Data for the Purpose of Order Handling
10.1 Insofar as necessary for the processing of the contract for delivery and payment purposes, the personal data collected by us will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 Para. 1 lit. b GDPR.
If we owe you updates for goods with digital elements or for digital products on the basis of a corresponding contract, we will process the contact data (name, address, e-mail address) provided by you when placing the order in order to inform you personally by suitable means of communication (e.g. by post or e-mail) about upcoming updates within the legally stipulated period of time within the framework of our statutory duty to inform pursuant to Art. 6 Para. 1 lit. c GDPR. Your contact details will be used strictly for the purpose of informing you about updates owed by us and will only be processed by us for this purpose to the extent that this is necessary for the respective information.
In order to process your order, we also work together with the following service provider(s), who support us in whole or in part in the execution of concluded contracts. Certain personal data is transferred to these service providers in accordance with the following information.
10.2 Use of Payment Service Providers
- Apple Pay
If you choose the payment method "Apple Pay" of Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, the payment processing is carried out via the "Apple Pay" function of your terminal device operated with iOS, watchOS or macOS by debiting a payment card deposited with "Apple Pay". Apple Pay uses security features built into the hardware and software of your device to protect your transactions. In order to release a payment, it is therefore necessary to enter a code previously defined by you and to verify it using the "Face ID" or "Touch ID" function of your terminal.
For the purpose of payment processing, your information provided during the ordering process, along with information about your order, will be transmitted to Apple in encrypted form. Apple then encrypts this data again with a developer-specific key before the data is transmitted to the payment service provider of the payment card stored in Apple Pay for payment processing. The encryption ensures that only the website from which the purchase was made can access the payment information. After the payment is made, Apple sends your device account number and a transaction-specific dynamic security code to the originating website to confirm the payment.
If personal data is processed in the described transmissions, the processing is carried out exclusively for the purpose of payment processing in accordance with Art. 6 Para. 1 lit. b GDPR.
Apple retains anonymised transaction data, including the approximate amount of the purchase, the approximate date and time and whether the transaction was completed successfully. Anonymisation completely excludes any personal reference. Apple uses the anonymised data to improve Apple Pay and other Apple products and services.
When you use Apple Pay on iPhone or the Apple Watch to complete a purchase made through Safari on Mac, the Mac and the authorization device communicate through an encrypted channel on Apple's servers. Apple does not process or store this information in any format that can identify you personally. You can disable the ability to use Apple Pay on your Mac in your iPhone preferences. Go to "Wallet & Apple Pay" and disable "Allow payments on Mac".
For more information about Apple Pay privacy, please visit the following web address: https://support.apple.com/en-gb/HT203027
- Google Pay
If you choose the payment method "Google Pay" of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), the payment processing is carried out via the "Google Pay" application of your mobile device running at least Android 4.4 ("KitKat") and having an NFC function by charging a payment card deposited at Google Pay or a payment system verified there (e.g. PayPal). For the release of a payment via Google Pay in the amount of more than 25,- € the prior unlocking of your mobile device by the respective verification measure (e.g. face recognition, password, fingerprint or pattern) is required.
For the purpose of payment processing, your information provided during the ordering process, together with the information about your order, will be forwarded to Google. Google then transmits your payment information stored in Google Pay in the form of a unique transaction number to the source website, which is used to verify a payment. This transaction number does not contain any information about the real payment data of your means of payment deposited with Google Pay, but is created and transmitted as a uniquely valid numeric token. For all transactions via Google Pay, Google acts merely as an intermediary to process the payment transaction. The transaction is carried out exclusively in the relationship between the user and the source website by debiting the means of payment deposited with Google Pay.
If personal data are processed in the described transmissions, the processing is carried out exclusively for the purpose of payment processing in accordance with Art. 6 para. 1 lit. b GDPR.
Google reserves the right to collect, store and evaluate certain transaction-specific information for each transaction made via Google Pay. This includes the date, time and amount of the transaction, the merchant's location and description, a description provided by the merchant of the goods or services purchased, photos that you have attached to the transaction, the name and email address of the seller and buyer or the sender and recipient, the payment method used, your description of the reason for the transaction and, if applicable, the offer associated with the transaction.
According to Google, this processing is carried out exclusively in accordance with Art. 6 para. 1 lit. f GDPR on the basis of the legitimate interest in proper accounting, verification of transaction data and optimisation and maintenance of the functionality of the Google Pay service.
Google also reserves the right to combine the processed transaction data with other information which is collected and stored by Google when using other Google services.
The terms of use of Google Pay can be found here:
https://payments.google.com/payments/apis-secure/u/0/get_legal_document?ldo=0&ldt=googlepaytos&ldl=en
Further information on data protection at Google Pay can be found here:
https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice&ldl=en
- Paypal
Online payment methods from the following provider are available on this website: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg
If you select a payment method of the provider for which you make an advance payment, your payment data provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order will be passed on to the provider in accordance with Art. 6 (1) point b GDPR. In this case, your data will only be passed on for the purpose of processing payment with the provider and only to the extent necessary for this purpose.
When selecting a payment method of the provider with which the provider makes advance payments, you will also be asked to provide certain personal data (first name and surname, street, house number, postcode, city, date of birth, e-mail address, telephone number, if applicable data on alternative means of payment) during the ordering process.
In order to safeguard our legitimate interest in determining the solvency of our customers, this data is passed on to the provider by us for the purpose of a credit check in accordance with Art. 6 (1) point f GDPR. On the basis of the personal data provided by you as well as further data (such as shopping cart, invoice total, order history, payment history), the provider checks whether the payment option selected by you can be granted with regard to payment and/or bad debt risks.
The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they have their basis in a scientifically recognised mathematical-statistical procedure. The calculation of the score values includes, but is not limited to, address data.
You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual processing of payments.
- Stripe
Online payment methods from the following provider are available on this website: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland
If you select a payment method of the provider for which you make an advance payment (e.g. credit card payment), your payment data provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order will be passed on to the provider in accordance with Art. 6 (1) point b GDPR. In this case, your data will only be passed on for the purpose of processing payment with the provider and only to the extent necessary for this purpose.
11) Web Analysis Services
11.1 Google Analytics 4
This website uses Google Analytics 4, a service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which can be used to analyze the use of websites.
When using Google Analytics 4, so-called "cookies" are used as standard. Cookies are text files that are stored on your terminal device and enable an analysis of your use of a website. The information collected by cookies about your use of the website (including the IP address transmitted by your terminal device, shortened by the last digits, see below) is usually transmitted to a Google server and stored and processed there. This may also result in the transmission of information to the servers of Google LLC, a company based in the USA, where the information is further processed.
When using Google Analytics 4, the IP address transmitted by your terminal device when you use the website is always collected and processed by default and automatically only in an anonymized manner, so that a direct personal reference of the collected information is excluded. This automatic anonymization is carried out by shortening the IP address transmitted by your terminal device by Google within member states of the European Union (EU) or other contracting states of the Agreement on the European Economic Area (EEA) by the last digits.
On our behalf, Google uses this and other information to evaluate your use of the website, to compile reports (reports) on your website activities or your usage behavior and to provide us with other services related to your website usage and internet usage. In this context, the IP address transmitted and shortened by your terminal device within the scope of Google Analytics 4 will not be merged with other data from Google. The data collected in the context of the use of Google Analytics 4 will be retained for 2 months and then deleted.
Google Analytics 4 also enables the creation of statistics with statements about age, gender and interests of website users on the basis of an evaluation of interest-based advertising and with the involvement of third-party information via a special function, the so-called "demographic characteristics". This makes it possible to determine and distinguish between groups of website users for the purpose of targeting marketing measures. However, data collected via the "demographic characteristics" cannot be assigned to a specific person and thus not to you personally. This data collected via the "demographic characteristics" function is retained for two months and then deleted.
All processing described above, in particular the setting of Google Analytics cookies for the storage and reading of information on the terminal device used by you for the use of the website, will only take place if you have given us your express consent for this in accordance with Art. 6 (1) lit. a GDPR. Without your consent, Google Analytics 4 will not be used during your use of the website.
You can revoke your consent once given at any time with effect for the future. To exercise your revocation, please deactivate this service via the "Cookie Consent Tool" provided on the website.
Google Signals
On this website, the "Google Signals" service can also be used as an extension of Google Analytics 4. With Google Signals, cross-device reports can be created by Google (so-called "cross-device tracking"). If you have activated "personalised ads" in your Google account settings and you have linked your internet-enabled devices to your Google account, Google can analyse user behaviour across devices and create database models based on this, provided you have given your consent to the use of Google Analytics in accordance with Art. 6 Para. 1 letter a GDPR (see above). The logins and device types of all page visitors who were logged into a Google account and performed a conversion are taken into account. The data shows, among other things, on which device you first clicked on an ad and on which device the associated conversion took place. Insofar as Google Signals is used, we do not receive any personal data from Google, but only statistics compiled on the basis of Google Signals. You have the option of deactivating the "personalised ads" function in the settings of your Google account and thus turning off the cross-device analysis. To do this, follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=de
Further information can be found here: https://support.google.com/analytics/answer/7532985?hl=de
User IDs
As an extension of Google Analytics 4, the "UserIDs" function can also be used on this website. By assigning individual UserIDs, we can have Google create cross-device reports (so-called "cross-device tracking"). This means that your usage behaviour can also be analysed across devices if you have given your corresponding consent to the use of Google Analytics in accordance with Art. 6 Para. 1 letter a GDPR, if you have set up a personal account by registering on this website and are logged into your personal account on different end devices with your relevant login data. The data collected in this way shows, among other things, on which end device you clicked on an ad for the first time and on which end device the relevant conversion took place.
We have concluded a so-called data processing agreement with Google for our use of Google Analytics 4, by which Google is obliged to protect the data of our website users and not to pass it on to third parties.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
Further legal information on Google Analytics 4 can be found here: https://policies.google.com/privacy?hl=en and https://business.safety.google/privacy/
Details on the processing triggered by Google Analytics 4 and Google's handling of data from websites can be found here: https://policies.google.com/technologies/partner-sites
11.2 Microsoft Clarity
This website uses the web analytics service provided by the following provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399 USA
Using cookies and/or comparable technologies (tracking pixels, web beacons, algorithms for reading end device and browser information), the service collects and stores pseudonymised visitor data, including information on the end device used such as the IP address and browser information, in order to evaluate it for statistical analyses of user behaviour on our website and to create pseudonymised user profiles. Among other things, this enables the analysis of movement patterns (so-called heat maps), which show the duration of page visits and interactions with page content (e.g. text entries, scrolling, clicks and mouse-overs). Pseudonymisation generally excludes the possibility of direct personal reference. Your personal data will not be combined with data collected in any other way.
All processing described above, in particular the reading or saving of information on the end device used, is only carried out if you have given us your express consent in accordance with Art. 6 (1) point a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "cookie consent tool" provided on the website.
We have concluded an order processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorised disclosure to third parties.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
12) Retargeting/Remarketing/ Referral Advertising
LinkedIn Marketing Solutions
This website uses retargeting technology from the following provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland
This enables us to target visitors to our website with personalized, interest-related advertising who have already shown interest in our shop and our products. The advertising material is displayed based on a cookie-based analysis of previous and current user behavior; whereby no personal data is stored. In the cases of retargeting technology, a cookie is stored on your computer or mobile device to collect pseudonymized data about your interests and thus adapt the advertising individually to the stored information. These cookies are small text files that are stored on your computer or mobile device. You are thus shown advertising that is most likely to match your product and information interests.
All processing described above, in particular the setting of cookies for reading out information on the end device used, will only be carried out if you have given us your express consent to do so in accordance with Art. 6 (1) point a GDPR. Without this consent, retargeting technology will not be used during your visit to the website.
You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "cookie consent tool" provided on the website.
13) Site Functionalities
13.1 Vimeo
This website uses plugins to display and play videos from the following provider: Vimeo.com, Inc., 330 West 34th Street, 10th Floor, New York, NY 10001, USA
When you call up a page of our website that contains such a plugin, your browser establishes a direct connection to the provider's servers to load the plugin. This involves certain information, including your IP address, being transmitted to the provider.
If the playback of embedded videos is started via the plugin, the provider also uses cookies to collect information about user behavior, to create playback statistics and to prevent abusive behavior.
If you are logged into a user account maintained by the provider during your visit to the site, your data will be directly assigned to your account when you click on a video. If you do not wish to have your data assigned to your account, you must log out before clicking on the play button.
All the above-mentioned processing, in particular the setting of cookies for reading out information on the end device used, only takes place if you have given us your express consent in accordance with Art. 6 (1) point a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service via the "cookie consent tool" provided on the website.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
13.2 YouTube Videos
This website uses plugins to display and play videos from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 ESW5, Ireland
Data may also be transmitted to: Google LLC., USA.
When you call up a page of our website that contains such a plugin, your browser establishes a direct connection to the provider's servers to load the plugin. This involves certain information, including your IP address, being transmitted to the provider.
If the playback of embedded videos is started via the plugin, the provider also uses cookies to collect information about user behavior, to create playback statistics and to prevent abusive behavior.
If you are logged into a user account maintained by the provider during your visit to the site, your data will be directly assigned to your account when you click on a video. If you do not wish to have your data assigned to your account, you must log out before clicking on the play button.
All the above-mentioned processing, in particular the setting of cookies for reading out information on the end device used, only takes place if you have given us your express consent in accordance with Art. 6 (1) point a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service via the "cookie consent tool" provided on the website.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
13.3 Facebook Connect
On our website we provide a single sign-on function offered by the following provider: Meta Platforms Ireland Limited, 4 Grand Canal Quary, Square, Dublin 2, Ireland
In addition to the transfer of data to the above-mentioned provider location, data may also be transferred to: Meta Platforms Inc, USA
If you have an account with the provider, you can use this account data to create a user account or to register on our website.
When you visit this page, a direct connection between your browser and the provider's servers can be established via this login function, even if you do not have an account with the provider or are not logged in to one. The provider thereby receives the information that you have visited our site. The information collected in this respect (including your IP address, if applicable) is transmitted by your browser directly to a server of the provider and stored there. However, the information is not used to identify you personally and is not passed on to third parties.
These data processing operations are carried out in accordance with Art. 6 (1) point f GDPR based on our legitimate interest in a user-friendly and interactive design of our online presence.
If you click on the registration button to register with your account data by logging into the provider's website, the provider will transmit the general and publicly accessible information stored in your account (user ID, name, address, e-mail address, age, and gender) to us based on your express consent pursuant to Art. 6 (1) point a GDPR.
We store and use the data transmitted by the provider to set up a user account containing the necessary data (title, first name, surname, address data, country, email address, date of birth), if you have released that data to the provider. Conversely, data (e.g., information about your surfing or purchasing behavior) may be transferred from us to your account held with the provider based on your consent.
The consent given can be revoked at any time with effect for the future vis-à-vis us.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
13.4 Google Sign-In
On our website we provide a single sign-on function offered by the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 ESW5, Ireland
In addition to the transfer of data to the above-mentioned provider location, data may also be transferred to: Google LLC, USA
If you have an account with the provider, you can use this account data to create a user account or to register on our website.
When you visit this page, a direct connection between your browser and the provider's servers can be established via this login function, even if you do not have an account with the provider or are not logged in to one. The provider thereby receives the information that you have visited our site. The information collected in this respect (including your IP address, if applicable) is transmitted by your browser directly to a server of the provider and stored there. However, the information is not used to identify you personally and is not passed on to third parties.
These data processing operations are carried out in accordance with Art. 6 (1) point f GDPR based on our legitimate interest in a user-friendly and interactive design of our online presence.
If you click on the registration button to register with your account data by logging into the provider's website, the provider will transmit the general and publicly accessible information stored in your account (user ID, name, address, e-mail address, age, and gender) to us based on your express consent pursuant to Art. 6 (1) point a GDPR.
We store and use the data transmitted by the provider to set up a user account containing the necessary data (title, first name, surname, address data, country, email address, date of birth), if you have released that data to the provider. Conversely, data (e.g., information about your surfing or purchasing behavior) may be transferred from us to your account held with the provider based on your consent.
The consent given can be revoked at any time with effect for the future vis-à-vis us.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
13.5 Google Maps
Our website uses Google Maps (AP’I) of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). Google Maps is a web service for displaying interactive (country) maps in order to display geographical information visually. Using this service will show you our location and will make it easier for you to find us.
When you access the sub-pages that contain the Google Maps map, information about your use of our website (such as your IP address) is transmitted to and stored by Google on servers. When using Google Maps, personal data may also be transmitted to the servers of Google LLC. in the USA. This is regardless of whether Google provides a user account that you are logged in with or whether no user account exists. If you are logged in to Google, your information will be directly associated with your account. If you do not wish to be associated with your profile on Google, you must log out before activating the button. Google saves your data (even for users who are not logged in) as usage profiles and evaluates them. Such an evaluation takes place according to Art. 6 (1) point f GDPR, on the basis of the legitimate interests of Google in the insertion of personalized advertising, market research and/or demand-oriented design of its website. You have the right to object to the creation of these user profiles. If you want to do so, you must contact Google to exercise this right.
If you do not agree to the future transmission of your data to Google in the context of using Google Maps, you may completely deactivate the Google Maps web service by switching off the JavaScript application in your browser. In this case, Google Maps as well as the map display on this website cannot be used.
The Google terms of use can be found at: https://policies.google.com/terms?hl=en. The additional terms of use can be found at: https://www.google.com/intl/en-US_US/help/terms_maps.html.
You can find detailed information on data protection in connection with the use of Google Maps on Google's website ("Google Privacy Policy") at: https://policies.google.com/privacy?hl=en.
To the extent required by law, we have obtained your consent to the processing of your data as described above in accordance with Art. 6 (1) point a GDPR. You can revoke your consent at any time with effect for the future. In order to exercise your revocation, please follow the procedure described above for submitting an objection.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
13.6 Adobe Fonts (Typekit)
This site uses so-called web fonts from the following provider to display fonts in a uniform manner: Adobe Systems Incorporated, 345 Park Avenue, San Jose, CA 95110-2704, USA
When you call up a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly and establishes a direct connection to the provider's servers. In this process, certain browser information, including your IP address, is transmitted to the provider.
The processing of personal data while establishing the connection with the provider of the fonts is only carried out if you have given us your express consent to do so in accordance with Art. 6 (1) point a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service via the "cookie consent tool" provided on the website. If your browser does not support web fonts, a standard font will be used by your computer.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
13.7 Google Web Fonts
This site uses so-called web fonts from the following provider to display fonts in a uniform manner: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
Data is also transferred to: Google LLC, USA
When you call up a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly and establishes a direct connection to the provider's servers. In this process, certain browser information, including your IP address, is transmitted to the provider.
The processing of personal data while establishing the connection with the provider of the fonts is only carried out if you have given us your express consent to do so in accordance with Art. 6 (1) point a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service via the "cookie consent tool" provided on the website. If your browser does not support web fonts, a standard font will be used by your computer.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
13.8 reCAPTCHA
On this website, we use the CAPTCHA service of the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
Data may also be transmitted to: Google LLC, USA. For the visual design of the CAPTCHA window, the provider uses "Google Fonts", i.e., fonts loaded from the Internet by Google. No further information is processed except that mentioned above, which is already transmitted to Google via the functionality of ReCaptcha.
The service checks whether an input is made by a natural person or abusively by machine and automated processing with the aim of blocking spam, DDoS attacks and similar automated malicious attacks. To ensure whether an action is performed by a human being and not by an automated bot, the provider collects the IP address of the end device used, the recognition data of the browser, the operating system type and the date and duration of the visit and transmits these data to the provider's servers to be evaluated.
This process is based on our legitimate interest in determining individual responsibility when using the Internet and in preventing abuse and spam in accordance with Art. 6 Para. 1 lit. f GDPR.
We have concluded an order processing contract with the provider, ensuring the protection of our site visitors' data and prohibiting unauthorized disclosure to third parties.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
13.9 Applications for job advertisements
On our website, we advertise current vacancies in a separate section, for which interested parties can apply by e-mail using the contact address provided.
If applicants want to be included in the application process, they must provide us with all personal details required for a well-founded and informed assessment and selection in conjunction with their application by e-mail.
The required data should include general personal information (name, address, telephone or electronic contact) as well as performance-specific evidence showing the qualifications required for the advertised position. In addition, health-related information may be required, which in the interest of social protection must be given special attention to regarding the applicant's person according to labor and social law.
The components an application must contain to be considered and the form in which these components must be sent by e-mail can be found in the respective job advertisement.
After receipt of the application sent using the e-mail contact address supplied, the applicant data will be stored by us and evaluated exclusively for the purpose of processing the application. In the event of queries arising in the course of processing the application, we will use either the e-mail address supplied by the applicant with his application or a telephone number supplied, at our discretion.
The legal basis for such processing, including the contacting of applicants for queries, is basically Art. 6 (1) point b GDPR in conjunction with Art. 26 (1) Federal Data Protection Act. According to these provisions, the completion of the application procedure is deemed to be the initiation of an employment contract.
If special categories of personal data within the meaning of Art. 9 (1) GDPR (e.g. health data such as information on severely disabled status) are requested from applicants as part of the application procedure, processing will take place in accordance with Art. 9 (2) point b GDPR, so as to enable us to exercise the rights arising from labor law, social security and social protection law and to fulfil our obligations in this regard.
The processing of special categories of data may also be based cumulatively or alternatively on Art. 9 (1) point h GDPR if it is used for the purposes of health care or occupational medicine, for the assessment of the applicant's ability to work, for medical diagnostics, health or social care or for the management of systems and services in the health or social sector.
If, in the course of the evaluation described above, the applicant is not selected or if an applicant withdraws his application prematurely, his data transmitted by e-mail as well as all electronic correspondence including the original application e-mail will be deleted at the latest after 6 months following a corresponding notification. This period shall be determined on the basis of our legitimate interest in being able to answer any follow-up questions regarding the application and, if necessary, to comply with our obligation to provide evidence under the regulations governing the equal treatment of applicants.
In the event of a successful application, the data provided will be processed on the basis of Art. 6 (1) point b GDPR in conjunction with Art. 26 (2) Federal Data Protection Act for the purposes of implementing the employment relationship.
13.10 Applications for job advertisements using a form
On our website, we offer those interested in a job the possibility to apply online using an appropriate form. In order to be included in the application process, applicants must provide us with all personal data required for a well-founded and informed assessment and selection.
The required data includes general personal information (name, address, telephone or electronic contact details) as well as performance-specific evidence of the qualifications required for a position. Where appropriate, health-related information may also be required, which, in the interests of social protection, must be given special consideration in the applicant's own person under labour and social law.
In the course of sending the form, the applicant's data will be encrypted according to the state of the art, transmitted to us, stored by us and evaluated exclusively for the purpose of processing the application.
The legal basis for these processing operations is generally Art. 6 Para. 1 lit. b, in the sense of which passing through the application procedure is considered to be the initiation of an employment contract.
Insofar as special categories of personal data within the meaning of Art. 9 para. 1 GDPR (e.g. health data such as information on the status of severely disabled persons) are requested from applicants in the context of the application procedure, processing is carried out in accordance with Art. Art. 9 para. 2 lit. b. GDPR so that we can exercise the rights arising from labour law and social security and social protection law and fulfil our obligations in this respect.
Cumulatively or alternatively, the processing of the special categories of data may also be based on Art. 9 para. 1 lit. h GDPR, if it is carried out for purposes of preventive health care or occupational medicine, for the assessment of the applicant's ability to work, for medical diagnosis, care or treatment in the health or social field or for the management of systems and services in the health or social field.
If, in the course of the evaluation described above, the applicant is not selected, or if an applicant withdraws his or her application prematurely, the data submitted on the application form will be deleted after 6 months at the latest after notification. This period is calculated on the basis of our legitimate interest in being able to answer any follow-up questions about the application and, if necessary, to comply with our obligation to provide evidence in accordance with the regulations on the equal treatment of applicants.
In the event of a successful application, the data provided will be further processed on the basis of Art. 6 para. 1 lit. b GDPR for the purposes of the employment relationship.
14) Rights of the Data Subject
14.1 The applicable data protection law grants you the following comprehensive rights of data subjects (rights of information and intervention) vis-à-vis the data controller with regard to the processing of your personal data:
- Right of access by the data subject pursuant to Art. 15 GDPR;
- Right to rectification pursuant to Art. 16 GDPR;
- Right to erasure (“right to be forgotten”) pursuant to Art. 17 GDPR;
- Right to restriction of processing pursuant to Art. 18 GDPR;
- Right to be informed pursuant to Art. 19 GDPR;
- Right to data portability pursuant to Art. 20 GDPR;
- Right to withdraw a given consent pursuant to Art. 7 (3) GDPR;
- Right to lodge a complaint pursuant to Art. 77 GDPR.
14.2 RIGHT TO OBJECT
IF, WITHIN THE FRAMEWORK OF A CONSIDERATION OF INTERESTS, WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR PREDOMINANT LEGITIMATE INTEREST, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THIS PROCESSING WITH EFFECT FOR THE FUTURE ON THE GROUNDS THAT ARISE FROM YOUR PARTICULAR SITUATION.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED. HOWEVER, WE RESERVE THE RIGHT TO FURTHER PROCESSING IF WE CAN PROVE COMPELLING REASONS WORTHY OF PROTECTION FOR PROCESSING WHICH OUTWEIGH YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FREEDOMS, OR IF THE PROCESSING SERVES TO ASSERT, EXERCISE OR DEFEND LEGAL CLAIMS.
IF WE PROCESS YOUR PERSONAL DATA FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA WHICH ARE USED FOR DIRECT MARKETING PURPOSES. YOU MAY EXERCISE THE OBJECTION AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED FOR DIRECT ADVERTISING PURPOSES.
15) Duration of Storage of Personal Data
The duration of the storage of personal data is based on the respective legal basis, the purpose of processing and - if relevant – on the respective legal retention period (e.g. commercial and tax retention periods).
If personal data is processed basis on an express consent pursuant to Art. 6 (1) point a GDPR, this data is stored until the data subject revokes his consent.
If there are legal storage periods for data that is processed within the framework of legal or similar obligations on the basis of Art. 6 (1) point b GDPR, this data will be routinely deleted after expiry of the storage periods if it is no longer necessary for the fulfillment of the contract or the initiation of the contract and/or if we no longer have a justified interest in further storage.
When processing personal data on the basis of Art. 6 (1) point f GDPR, this data is stored until the data subject exercises his right of objection in accordance with Art. 21 (1) GDPR, unless we can provide compelling grounds for processing worthy of protection which outweigh the interests, rights and freedoms of the data subject, or the processing serves to assert, exercise or defend legal claims.
If personal data is processed for the purpose of direct marketing based on Art. 6 (1) point f GDPR, this data is stored until the data subject exercises his right of objection pursuant to Art. 21 (2) GDPR.
Unless otherwise stated in the information contained in this declaration on specific processing situations, stored personal data will be deleted if it is no longer necessary for the purposes for which it was collected or otherwise processed.