Skip to main content Skip to search Skip to main navigation
free shipping from 150,- EUR within Germany | 100 days return | Hotline: +49 351 810 62 12
Go to homepage
since 2004
Hotline Mo-Fr: 9-18 o'clock

Privacy

Controller:

Diana Berthold, Hairoyal company, Schlesischer Platz 2, D-01097 Dresden, Phone: +49 351 810 62 12, Fax: +49 351 810 62 14, Email: info@hairoyal.de.

1. Scope and Legal Basis

(1) This privacy policy informs you about the type, scope, and purpose of the processing of personal data within our online offering and the associated websites, functions, and content.

(2) With regard to the terminology used, such as “personal data” or “processing” thereof, we refer to the definitions in Art. 4 of the „Datenschutzgrundverordnung (DSGVO)“.

(3) The term “user” includes all categories of persons affected by data processing. These include our business partners, customers, prospects, and other visitors to our online offering.

(4) The personal data processed within this online offering includes:

  • inventory data (e.g., names and addresses of customers),
  • contact data (e.g., email address, telephone number),
  • contract data (e.g., services used),
  • usage data (e.g., websites of our online offering visited, interest in our services),
  • content data (e.g., input in forms, etc.), as well as
  • technical data (e.g., IP addresses, device information)

(5) The processing of users’ personal data is carried out in particular for the following purposes:

  • provision of the online offering, its content and functions,
  • provision of our contractual services and services,
  • customer care,
  • answering contact requests and communication with users,
  • marketing, as well as
  • security of the online offering.

(6) We process users’ personal data only in compliance with the relevant data protection regulations. This means that users’ data is only processed if there is legal permission. This is particularly the case when data processing is necessary for the performance of contractual services (e.g., processing orders and purchases) as well as our online services, or is legally required, or based on consent from users, or based on our legitimate interests. Legitimate interests include analysis, optimization, security, and the economic operation of our online offering.

(7) We note that the legal basis for consent is Art. 6 (1) sentence 1 lit. a) and Art. 7 GDPR, the legal basis for processing for the performance of our services and execution of contractual measures is Art. 6 (1) sentence 1 lit. b) GDPR, the legal basis for processing to fulfill legal obligations is Art. 6 (1) sentence 1 lit. c) GDPR, and the legal basis for processing to safeguard our legitimate interests is Art. 6 (1) sentence 1 lit. f) GDPR.

(8) The storage of information in the user’s terminal equipment or access to information already stored in the user’s terminal equipment is also only permitted if covered by one of the justification grounds under § 25 TTDSG. These are in particular § 25 (1) TTDSG, if the user has given consent based on clear and comprehensive information, or § 25 (2) No. 2 TTDSG, if storage or access is strictly necessary for the provider of a telemedia service to provide a telemedia service expressly requested by the user.

2. Security Measures

(1) We take appropriate technical and organizational measures in accordance with Art. 32 GDPR, taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of processing, as well as the varying likelihood and severity of risk to the rights and freedoms of natural persons, in order to ensure an appropriate level of protection. This is intended in particular to protect the data we process against accidental or intentional manipulation, loss, deletion, or unauthorized access by third parties. Security measures also include encrypted transmission of data between your browser and our server.

(2) In addition, we have established procedures that ensure the exercise of data subject rights, the deletion of data, and responses to risks to data.

3. Disclosure of Data to Third Parties and Third Providers

(1) If, in the course of our processing, we disclose data to other persons and companies (processors or third parties), transfer it to them, or otherwise grant them access to the data, this is done only on the basis of legal permission. This applies, for example, to transfers of data pursuant to Art. 6 (1) sentence 1 lit. b) GDPR to third parties if this is necessary for contract fulfillment (e.g., for shipping goods), if you have consented, if a legal obligation provides for this, or on the basis of our legitimate interests (e.g., use of service providers, web hosts, payment service providers, etc.). If you use third-party payment services, you must log in to the selected payment service provider during the order process using your access data or register for the first time. The terms and conditions and privacy notices of the respective payment service provider apply, which can be accessed on their websites or transaction applications.

(2) If we process data in a third country (i.e., outside the European Union or the European Economic Area) or this occurs in the context of using third-party services or disclosure/transfer of data to third parties, this is only done if the special requirements of Art. 44 et seq. GDPR are met. Some third countries are certified by the European Commission via so-called adequacy decisions as having a level of data protection comparable to the EEA standard (a list of these countries and copies of the adequacy decisions can be found here: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en). For transfers of personal data to the USA, the European Commission has adopted the so-called EU-US Data Privacy Framework. In other third countries to which personal data may be transferred, there may, however, be no consistently high level of data protection due to the absence of legal provisions. In such cases, data protection may be ensured by other measures, such as binding corporate rules, standard contractual clauses of the European Commission for the protection of personal data pursuant to Art. 46 (1), (2) lit. c GDPR, certifications, or recognized codes of conduct. We inform you of the respective details of such transfers at the relevant points below.

(3) If we commission third parties with the processing of data on the basis of a so-called “data processing agreement,” this is done on the basis of Art. 28 GDPR.

4. Collection of Access Data and Log Files

(1) We collect, on the basis of our legitimate interests within the meaning of Art. 6 (1) lit. f) GDPR, data about every access to the server on which this service is located (so-called server log files). These data are technically necessary to display the respective website to you as well as to ensure stability and security. Access data includes in particular the name of the retrieved website, file, date and time of retrieval, amount of data transferred, notification of successful retrieval, browser type and version, the user’s operating system, the previously visited website, and the IP address.

(2) Log file information is stored for security reasons (e.g., to clarify cases of misuse or fraud) for a maximum of 7 days and then deleted. Data whose further storage is required for evidentiary purposes is exempt from deletion until the respective incident has been finally clarified.

5. Provision of Contractual Services

(1) We process inventory data, contact data, contract data, and content data for the purpose of fulfilling our contractual obligations and services pursuant to Art. 6 (1) sentence 1 lit. b) GDPR. The mandatory entries marked as such in online forms are required for the conclusion of a contract.

(2) Users may optionally create a user account in which they can, among other things, view their orders. During registration, the required mandatory information is communicated to users. The legal basis for opening and maintaining your user account is your consent pursuant to Art. 6 (1) sentence 1 lit. a) GDPR. If users terminate their user account (this is possible at any time via email, fax, or letter using the contact details provided above), their data relating to the user account will be deleted, unless further storage is required due to legal obligations, in particular commercial or tax law obligations pursuant to Art. 6 (1) sentence 1 lit. c) GDPR.

(3) During registration and subsequent login as well as when using our online services (e.g., during orders), we store the user’s IP address and the time of the order. This storage is carried out on the basis of our legitimate interests as well as the users’ interest in protection against misuse and other unauthorized use. This data is generally not passed on to third parties unless it is necessary for the enforcement of our claims or there is a legal obligation pursuant to Art. 6 (1) sentence 1 lit. c) GDPR. The stored data is deleted after 30 days. Data whose further storage is required for evidentiary purposes is exempt from deletion until the respective incident has been finally clarified.

(4) The deletion of data for the provision of contractual services takes place after expiration of statutory warranty and comparable obligations. In the case of statutory retention obligations, deletion occurs after their expiration (end of commercial law retention period of 6 years and tax law retention period of 10 years). Data in the customer account remains until it is deleted.

6. Payment Procedures, Credit Checks

(1) In connection with contract conclusion, we offer users efficient and secure payment options and use payment service providers in addition to banks and credit institutions.

(2) The data processed by payment service providers includes inventory data, bank data such as account or credit card numbers, passwords, TANs, and checksum data as well as contract data. These details are required to process payment transactions. However, the entered data is processed only by the respective payment service provider and stored by them. In other words, we do not receive any account or credit card-related information, but only information confirming or rejecting the payment. Under certain circumstances, payment service providers may transmit data to credit agencies for the purpose of identity and credit checks. In this respect, we refer to the terms and privacy policies of the payment service providers. The same applies to further information as well as the assertion of rights of access, withdrawal, and other data subject rights.

(3) The purpose of processing is the provision of contractual services and customer service; the legal basis is Art. 6 (1) sentence 1 lit. b) GDPR.

(4) We use the following payment service providers:

  • PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg); website: https://www.paypal.com/de; privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
  • Stripe (Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA); website: https://stripe.com; privacy policy: https://stripe.com/de/privacy. Stripe uses servers that may also be located outside the European Union (e.g., in the USA). However, Stripe ensures an adequate level of data protection, including by concluding EU Standard Contractual Clauses. Stripe is also certified under the EU-US Data Privacy Framework.

7. Contacting Us

When contacting us via contact form or email, the user’s details (your email address, your name, the content of the message, and possibly your telephone number, company, or other voluntarily provided data) are processed for handling the contact request and its processing pursuant to Art. 6 (1) sentence 1 lit. b) GDPR (within pre-contractual/contractual relationships) or, in the case of other inquiries, on the basis of our legitimate interest pursuant to Art. 6 (1) sentence 1 lit. f) GDPR in providing you with good service. The mentioned data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. This is usually the case when the respective conversation with the user has ended. The conversation is considered ended when it can be inferred from the circumstances that the relevant matter has been conclusively clarified. Otherwise, statutory retention obligations apply.

8. Chat Function

(1) We offer users of our online service a live chat system as a communication option. This enables online conversation or answering user inquiries.

(2) When using the chat system, we may collect and store information about when and, if applicable, which user communicated with us via the chat system. The content of the conversation is stored, and consent processes are logged in order to be able to prove them. In addition, the service provider may collect technical user data for the purpose of optimizing and securing the service, whereby cookies may be used.

(3) Messages exchanged via the chat system are deleted as soon as they are no longer required for the purpose for which they were collected. This is usually the case when the respective conversation has ended. The conversation is considered ended when it can be inferred from the circumstances that the matter in question has been conclusively clarified. Otherwise, statutory retention obligations apply.

(4) The purpose of processing is responding to contact requests/communication with users, including the provision of contractual services and customer service. The legal basis is Art. 6 (1) sentence 1 lit. a) GDPR (in conjunction with § 25 TTDSG regarding the use of cookies). Consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

(5) We use the live chat system of tawk.to Inc. (187 East Warm Springs Rd, SB298, Las Vegas, NV 89119, USA); website: https://www.tawk.to/; privacy policy: https://www.tawk.to/privacy-policy/; basis for third-country transfer: EU-US Data Privacy Framework.

9. Newsletter

(1) With the following information, we inform you about the content of our newsletter as well as the registration and dispatch procedure and your rights of objection. By subscribing to our newsletter, you agree to receive it and to the described procedures.

(2) We send newsletters containing advertising information by email only with the consent of the recipients or on the basis of a legal permission. Our newsletters contain information about our products and services, promotions, and our company.

(3) Registration for our newsletter takes place in a so-called double opt-in procedure. This means that after registration you will receive an email asking you to confirm your subscription. This confirmation is necessary so that no one can register with someone else’s email address. Newsletter registrations are logged in order to be able to prove the registration process in accordance with legal requirements. This includes storing the registration and confirmation time as well as the IP address. The purpose of the procedure is to be able to prove your registration and, if necessary, to clarify possible misuse of your personal data. This is carried out on the basis of Art. 6 (1) sentence 1 lit. f) GDPR.

(4) The newsletter is sent using “MailChimp,” a newsletter dispatch platform of the US provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA. Website: https://mailchimp.com/de/; privacy policy: https://mailchimp.com/de/legal/. Basis for third-country transfer: EU-US Data Privacy Framework.

(5) Subscription to the newsletter takes place during the ordering process by clicking the corresponding opt-in field or via the corresponding form within our online offering. There, providing your email address for sending the newsletter as well as your first and last name for personal addressing in the newsletter is required.

(6) The newsletters contain a so-called “web beacon,” i.e., a pixel-sized file that is retrieved from the server of the dispatch service provider when the newsletter is opened. During this retrieval, technical information such as information about the browser and your system as well as your IP address and time of retrieval are collected. This information is used for technical improvement of services based on technical data or target groups and their reading behavior based on their retrieval locations (determined via IP address) or access times. Statistical analysis also includes determining whether newsletters are opened, when they are opened, and which links are clicked. This information can technically be assigned to individual newsletter recipients. However, neither we nor the dispatch service provider intend to monitor individual users. The evaluations are used solely to recognize reading habits of our users and to adapt our content or send different content according to user interests.

(7) Newsletter dispatch and performance measurement are carried out on the basis of consent pursuant to Art. 6 (1) sentence 1 lit. a), Art. 7 GDPR.

(8) You may revoke your consent to receive the newsletter at any time. A link for revocation can be found at the end of each newsletter. You may also unsubscribe via the corresponding form within our online offering. We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests pursuant to Art. 6 (1) sentence 1 lit. f) GDPR before deleting them in order to be able to prove a previously given consent. Processing of this data is limited to the purpose of possible defense against claims. An individual deletion request is possible at any time provided that previous consent is confirmed.

10. Cookies

(1) We use cookies on our websites. Cookies are small text files or other storage records that store information on end devices and read information from end devices. Cookies cannot execute programs or transmit viruses to your device and therefore cannot cause damage. They are used to make the internet offering more user-friendly and effective overall.

(2) Cookies may contain data that enables recognition of the device used. In some cases, cookies contain only information about certain settings that are not personally identifiable. However, cookies cannot directly identify a user.

(3) A distinction is made between session cookies, which are deleted when you close your browser, and persistent cookies, which remain stored beyond a session. Cookies are also distinguished by function. We use functional or strictly necessary cookies that enable basic functions and are required for the proper functioning of our websites, marketing cookies used to display targeted advertising across multiple page views and browser sessions, tracking cookies used to collect and evaluate information about how our online offering is used (e.g., which pages are visited), and service cookies used to integrate additional services such as live chat systems or payment providers.

(4) The legal basis for cookies that are strictly necessary to provide you with the explicitly requested service is § 25 (2) No. 2 TTDSG. Any use of cookies that is not strictly technically necessary constitutes data processing that is only permitted with explicit and active consent pursuant to § 25 (1) TTDSG in conjunction with Art. 6 (1) sentence 1 lit. a) GDPR.

(5) We use a cookie consent management system. In this process, user consent for the use of cookies and related processing is obtained and managed, and consent can be withdrawn. For this purpose, the consent declaration is stored in order to avoid repeated requests and to be able to prove consent in accordance with legal requirements. Storage takes place via functional cookies. If you wish to withdraw your consent, simply delete the cookie in your browser or use the cookie consent tool available on each website. When you re-enter or reload the website, you will again be asked for consent.

(6) Further information about cookies used within our online offering, in particular name, provider, expiration date (storage duration), and description of the cookie, can be found in the cookie consent tool.

11. Google Analytics and Google Tag Manager

(1) We use Google Analytics to measure and analyze the use of our online offering. Google Analytics collects data about your usage actions within our online offering based on a pseudonymous user identification number. This identification number does not contain any personal data. It is used in particular to assign collected information to a specific device. In addition to user actions such as page views, clicks, scrolling, or search term input, the time of use, duration, and technical information about devices and browsers are stored. Based on this information, pseudonymous user profiles are created, and cookies may also be used.

(2) According to Google, no IP addresses are logged or stored in Google Analytics. However, location is derived from the IP address by capturing metadata such as “city,” “continent,” “country,” and “region.” Google receives and processes user data via domains and servers within the European Union.

(3) The processing of usage and technical data collected via Google Analytics is for the purpose of reach measurement and improving our online offering, including usability. The legal basis is Art. 6 (1) sentence 1 lit. a) GDPR (in conjunction with § 25 TTDSG regarding cookies). Consent may be revoked at any time.

(4) Provider of Google Analytics is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; website: https://marketingplatform.google.com/intl/de/about/analytics/; privacy policy: https://policies.google.com/privacy; basis for third-country transfer: Data Privacy Framework; opt-out option: https://tools.google.com/dlpage/gaoptout?hl=de.

(5) We also use Google Tag Manager on the basis of consent pursuant to Art. 6 (1) sentence 1 lit. a) GDPR. This is a solution that allows website tags to be managed via an interface and other services to be integrated into our online offering. The Tag Manager itself does not create user profiles or use cookies. Only the user’s IP address is transmitted to Google, which is necessary for the functionality of the Tag Manager. Provider: Google Ireland Limited; privacy policy: https://policies.google.com/privacy; basis for third-country transfer: EU-US Data Privacy Framework.

12. Google AdSense

(1) Within our online offering, we use the online advertising service Google AdSense, through which users may be shown interest-based banner advertising to inform them about our products. Advertisements are marked as such. The legal basis for processing is Art. 6 (1) sentence 1 lit. a) GDPR, meaning integration only occurs with user consent.

(2) By visiting our online offering, Google receives the information that the user has accessed our website. For this purpose, Google uses a small text file in the source code of our online offering to place a cookie on the user’s device. Technical data such as IP address and time are transmitted to Google. We allow Google to collect necessary information for displaying suitable ads, but we have no knowledge of the extent of data collection or storage duration. If the user is logged into a Google account, data may be directly associated with the profile. If this is not desired, the user must log out beforehand.

(3) Revocation of consent is possible at any time without affecting the lawfulness of processing prior to revocation. Revocation can be carried out via the cookie consent tool or via browser settings and Google ad settings.

(4) Provider: Google Ireland Limited; privacy policy: https://policies.google.com/privacy; basis for third-country transfer: Data Privacy Framework.

13. Use of the Meta Pixel

(1) We use our online offering for advertising measures by Meta. By integrating the so-called “Meta Pixel,” we can display advertising (“Meta ads”) to users and measure and evaluate their success (“conversion tracking”). This connection is established technically via the Meta Pixel. Legal basis is Art. 6 (1) sentence 1 lit. a) GDPR, meaning integration only occurs with user consent.

(2) Due to the marketing tools used, the user’s browser automatically establishes a direct connection to Meta’s server when visiting our online offering. We have no influence on the scope and further use of data collected by Meta. According to Meta, integration of the pixel informs Meta that the user has visited our website or clicked an advertisement. If the user is registered with Meta, Meta may assign the visit to the account. Even if not registered or logged in, Meta may process IP address and other identifiers for profiling.

(3) We also use the remarketing function “Custom Audiences,” which also uses the Meta Pixel to display interest-based ads.

(4) We and Meta may be joint controllers under Art. 26 GDPR for certain processing operations, particularly data collection and transmission for measurement, analysis, and optimization of advertising.

(5) The joint controllership agreement and terms for Meta Business Tools apply.

(6) Users may exercise rights against us or Meta; Meta is primarily responsible for further processing after transmission.

(7) Data may be stored on Meta servers in the USA under Data Privacy Framework.

(8) Consent may be revoked at any time via cookie tool or platform settings.

(9) Provider: Meta Platforms Ireland Limited; privacy policy: https://www.facebook.com/privacy/policy/

14. TikTok Pixel

(1) We also use our online offering for advertising measures by TikTok. By integrating the so-called “TikTok Pixel,” we can display our advertising measures to users of our online offering and the social network TikTok and measure and evaluate their success. This connection between TikTok and our online offering is technically established via the “TikTok Pixel.” The legal basis for the processing of user data is Art. 6 (1) sentence 1 lit. a) GDPR, i.e., integration only takes place with the user’s consent.

(2) Due to the marketing tool used, the user’s browser automatically establishes a direct connection to TikTok’s server when visiting our online offering. We have no influence on the scope and further use of the data collected by TikTok through the use of this tool. According to TikTok, integration of the pixel provides TikTok with information that the user has accessed the corresponding page of our online offering or clicked on an advertisement from us.

(3) Revocation of user consent is possible at any time without affecting the lawfulness of processing carried out prior to revocation. Revocation can be carried out via our cookie consent tool.

(4) Service provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland and TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London, United Kingdom, EC1A 9HP; website: https://www.tiktok.com; privacy policy: https://www.tiktok.com/de/privacy-policy.

15. Microsoft Ads

(1) We use the service Microsoft Advertising for our online offering. Microsoft Advertising is an online marketing service that supports us via the Universal Event Tracking (UET) tool in displaying advertisements via the Microsoft Bing search engine in a targeted manner and analyzing subsequent user behavior when users reach our online offering via a Microsoft Advertising advertisement. This is done for the purpose of optimizing the placement of advertisements. The legal basis for processing user data is Art. 6 (1) sentence 1 lit. a) GDPR, i.e., integration only takes place with user consent.

(2) When using Microsoft Advertising, cookies may be used and data (IP address, time of visit, device and browser information, and information about the use of our online offering) may be collected, from which usage profiles are created under pseudonyms. If the user is registered with a Microsoft service and the “interest-based advertising” setting is not disabled in their Microsoft account, Microsoft may create reports on usage behavior (in particular cross-device user numbers). We do not process personal data in this respect; we only receive statistics generated based on Microsoft UET.

(3) Revocation of consent is possible at any time without affecting the lawfulness of processing prior to revocation. Revocation can be carried out via our cookie consent tool.

(4) Service provider: Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; website: https://about.ads.microsoft.com/de-de/h/a/microsoft-advertising; privacy policy: https://privacy.microsoft.com/de-de/privacystatement.

16. Embedding of YouTube Videos

(1) We have embedded YouTube videos into our online offering that are stored on https://youtube.com and can be played directly from our website. The videos are embedded in “extended privacy mode,” meaning that no data about you as a user is transferred to YouTube if you do not play the videos. Only when you play the videos are the data mentioned in paragraph 2 transmitted. We have no influence on this data transmission. The legal basis for displaying the videos is Art. 6 (1) sentence 1 lit. a) GDPR, i.e., integration only takes place with your consent.

(2) By visiting the website, YouTube receives the information that you have accessed the corresponding subpage of our website. In addition, the basic data mentioned above, such as IP address and timestamp, are transmitted. This occurs regardless of whether you are logged into a user account provided by YouTube or not. If you are logged into Google, your data is directly assigned to your account. If you do not want this assignment to your YouTube profile, you must log out before activating the video. YouTube processes your data (even for non-logged-in users) as usage profiles and uses it for market research, personalized advertising, website design, and/or to inform other users about your activities on our website. You have the right to object to the creation of these user profiles, which must be exercised directly with YouTube.

(3) The collected information is processed on Google servers, including in the USA. For these cases, the provider has committed to the EU-US Data Privacy Framework.

(4) Further information about purpose and scope of data collection and processing by YouTube can be found in YouTube’s privacy policy.

(5) Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; website: https://www.youtube.com; privacy policy: https://www.youtube.com/t/privacy.

17. Integration of the Trusted Shops Trustbadge

(1) To display our Trusted Shops seal of approval and to offer Trusted Shops products to buyers after an order, the Trusted Shops Trustbadge is integrated into our online offering. The legal basis for the associated processing of user data is Art. 6 (1) sentence 1 lit. a) GDPR, i.e., integration only takes place with user consent.

(2) The Trustbadge and the services advertised with it are an offer of Trusted Shops AG (“Trusted Shops”), with which we are jointly responsible under Art. 26 GDPR. Below we inform you about the essential contractual content pursuant to Art. 26 (2) GDPR.

(3) Within the framework of joint responsibility between us and Trusted Shops AG, please direct data protection inquiries and the assertion of your rights preferably to Trusted Shops using the contact options provided in the privacy information (https://www.trustedshops.de/impressum-datenschutz/#datenschutz). Regardless of this, you may always contact the controller of your choice. Your request will then be forwarded to the other controller if necessary.

(4) The Trustbadge is provided by a US-based CDN provider (content delivery network). An adequate level of data protection is ensured through standard contractual clauses and other contractual measures. When the Trustbadge is accessed, the web server automatically stores a so-called server log file, which also contains the IP address, date and time of access, transferred data volume, and requesting provider (access data). The IP address is anonymized immediately after collection so that the stored data cannot be assigned to the user. The anonymized data is used in particular for statistical purposes and error analysis.

(5) After order completion, the Trustbadge accesses order information stored on the user’s device (order total, order number, possibly purchased product) as well as the email address, which is hashed using a cryptographic one-way function. The hash value is then transmitted together with the order information to Trusted Shops in accordance with Art. 6 (1) sentence 1 lit. a) GDPR. This serves to verify whether the user is already registered for Trusted Shops services. If this is the case, further processing takes place according to the contractual agreement between the user and Trusted Shops pursuant to Art. 6 (1) sentence 1 lit. b) GDPR. If the user is not yet registered or has not given consent for automatic recognition via the Trustbadge, they will subsequently be given the option to register manually or to conclude buyer protection within an existing contract. The Trustbadge accesses the following information stored on the user’s device after order completion: order total, order number, and email address. This is necessary in order to offer buyer protection. Data is transmitted to Trusted Shops only if the user actively chooses buyer protection by clicking the corresponding button in the Trustcard. If the user chooses to use the services, further processing is governed by the contractual agreement with Trusted Shops pursuant to Art. 6 (1) sentence 1 lit. b) GDPR.

(6) Service provider: Trusted Shops AG, Subbelrather Str. 15C, 50823 Cologne; website: https://www.trustedshops.de; privacy policy: https://www.trustedshops.de/impressum/#datenschutz.

18. Embedding of Google Maps

(1) We integrate maps from the Google Maps service provided by Google. This is done on the basis of our legitimate interests (i.e., interest in optimizing and economically operating and user-friendly provision of our online offering within the meaning of Art. 6 (1) lit. f GDPR).

(2) The integration of Google Maps takes place via a server request to Google (usually in the USA). This always requires that Google perceives the user’s IP address, as otherwise it could not transmit the content to the browser. The IP address is therefore necessary for displaying the maps. Location data may also be part of the data processed by Google.

(3) Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; website: https://mapsplatform.google.com/; privacy policy: https://policies.google.com/privacy; basis for third-country transfer: EU-US Data Privacy Framework.

19. Shopware Analytics

(1) Together with our shop software service provider, we evaluate certain information from our customer base under joint controllership (e.g., customer group, pages visited, click paths, date and time of visit, information about the device used (resolution, pixel density, operating system), referrer URL, information about the browser used, locale, search queries, and time zone). This information is processed by an external service provider and transmitted to us in near real time so that we can monitor the use of our website and improve our offerings.
Legal basis: Art. 6 (1) lit. f GDPR
Data categories: derived data from master and contact data (customer group, no individual customer data), usage data, connection data
Recipients of the data: shopware AG, Ebbinghoff 10, 48624 Schöppingen, Germany (as joint controller), IT service providers
Essential nature of joint controllership: The joint controllership exists between us and shopware AG; the data is collected on our shop and then transmitted to Shopware or its service providers’ servers; except for obtaining your consent for the use of cookies or similar technologies and fulfilling these information obligations, all obligations, in particular the implementation of data subject rights, are the responsibility of shopware AG, which you can contact at legal@shopware.com. You may also assert your rights with us, and we will forward your request to shopware AG accordingly. shopware AG may derive behavioral patterns from the collected data in our store but cannot assign this data to you as a person.
Intended third-country transfer: None

(2) Do we store personal data on your device based on your consent or read such data?
Yes, details see consent management.

18. Shopware Analytics

(1) Wir werten zusammen mit unserem Shopsoftware-Dienstleister in gemeinsamer Verantwortlichkeit bestimmte Informationen unseren Kundenbestands aus (z.B. die Kundengruppe, besuchte Seiten, Klickpfade, Datum und Uhrzeit des Besuches, Informationen über das genutzte Endgerät (Auflösung, Auflösungsdichte, Betriebssystem), Referrer URL, Informationen des verwendeten Browsers, Gebietsschema, Suchanfragen und die Zeitzone). Diese Informationen werden durch einen externen Dienstleister aufbereitet und uns in näherungsweise Echtzeit zugeleitet, damit wir die Nutzung unserer Website überwachen und unsere Angebote verbessern können. 
Rechtsgrundlage: Art. 6 Abs. 1 Buchst. f DSGVO
Datenkategorien: Ableitungen aus Stamm- und Kontaktdaten (die Kundengruppe, keine individuellen Kundendaten), Nutzungsdaten, Verbindungsdaten
Empfänger der Daten: shopware AG, Ebbinghoff 10, 48624 Schöppingen, Deutschland (als gemeinsam Verantwortlicher), IT-Dienstleister
Das Wesentlich der gemeinsamen Verantwortlichkeit: Die gemeinsame Verantwortlichkeit besteht zwischen uns und der shopware AG; die Daten werden auf unserem Shop erhoben und sodann auf Server der Shopware bzw. deren Dienstleister übertragen; mit Ausnahme der Einholung Ihrer Einwilligung für den Einsatz von Cookies oder vergleichbaren Technologien sowie die Erfüllung dieser Informationspflichten obliegen alle Pflichten, insbesondere die Umsetzung der Betroffenenrechte, der shopware AG, die Sie unter legal@shopware.com erreichen können. Sie können Ihre Betroffenenrechte auch bei uns geltend machen, wir werden Ihre Anfrage dann entsprechend an die shopware AG weiterleiten. Die shopware AG kann aus den erhobenen Daten Verhaltensweisen auf unserem Store ableiten, diese Daten jedoch nicht Ihnen als Person zuordnen.
Beabsichtigte Drittlandübermittlung: Keine

(2) Speichern wir auf Ihrem Endgerät aufgrund Ihrer Einwilligung personenbezogene Daten oder lesen solche aus?
Ja, Details siehe Consent Management.

20. Online Presences in Social Networks

(1) We maintain an online presence within the social networks Facebook as well as TikTok in order to communicate with our users and to present ourselves and our services.

(2) There is a possibility that user data may be processed outside the European Union, which may involve risks, e.g. in enforcing user rights. However, Facebook is certified under the EU-US Data Privacy Framework and has committed to comply with EU data protection standards.

(3) Through the websites within social networks, user data may be processed for analysis and advertising purposes. It is possible to create anonymous usage profiles based on user behavior and resulting interests, which are then used to display advertisements within and outside the social network that correspond to presumed user interests. For these purposes, cookies are generally used and stored on users’ devices containing information about usage behavior and interests. In addition, device-independent data may also be stored in usage profiles, especially if users are members of the respective social network and logged in.

(4) The operation of online presences in social networks and the associated data processing is based on our legitimate interests (provision of interesting information outside our online offering, further communication options with users/interested parties) pursuant to Art. 6 (1) sentence 1 lit. f GDPR.

(5) For a detailed description of the respective processing operations and opt-out options, we refer users to the information provided by the operators of the respective social networks below.

(6) Facebook pages: Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; website: https://www.facebook.com; privacy policy: https://www.facebook.com/about/privacy; basis for third-country transfer: EU-US Data Privacy Framework. We are jointly responsible with Meta Platforms Ireland Limited for the collection (but not further processing) of data of visitors to our Facebook page. This includes information about types of content users view or interact with or actions taken, as well as technical data. Facebook also uses this data to provide so-called “Page Insights” to page operators. A special agreement exists between us and Facebook regarding Page Insights. Further information: https://www.facebook.com/legal/terms/information_about_page_insights_data.

(7) TikTok pages: Service provider: TikTok Technology Limited and TikTok Information Technologies UK Limited; website: https://www.tiktok.com; privacy policy: https://www.tiktok.com/de/privacy-policy.

(8) Instagram: Service provider: Meta Platforms Ireland Limited; website: https://www.instagram.com; privacy policy: https://privacycenter.instagram.com/policy/.

(9) YouTube: Service provider: Google Ireland Limited; website: https://www.youtube.com/; privacy policy: https://business.safety.google/privacy/; opt-out: https://myadcenter.google.com/.

21. Your Rights

Where the respective legal requirements are met, you have the following rights:

(1) You have the right to request confirmation from us as to whether personal data concerning you is being processed; if this is the case, you have the right to access such personal data and the information listed in detail in Art. 15 GDPR.

(2) You have the right to request the rectification of inaccurate personal data concerning you without undue delay and, where applicable, the completion of incomplete personal data (Art. 16 GDPR).

(3) You have the right to request the deletion of personal data concerning you without undue delay, provided that one of the reasons listed in Art. 17 GDPR applies, for example if the data is no longer necessary for the purposes pursued (right to erasure).

(4) You have the right to request restriction of processing if one of the conditions listed in Art. 18 GDPR is met, for example if you have objected to processing for the duration of the review.

(5) You have the right to object at any time to processing of personal data concerning you for direct marketing purposes. You also have the right to object to processing based on Art. 6 (1) sentence 1 lit. e or f GDPR on grounds relating to your particular situation (Art. 21 GDPR).

(6) You have the right to withdraw consent at any time with effect for the future.

(7) You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format and to transmit those data to another controller (right to data portability).

(8) Please contact our data protection officer using the contact details provided above to exercise your rights.

(9) Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of personal data concerning you infringes the GDPR (Art. 77 GDPR).

22. Right to Object

(1) You have the right to object at any time to processing of personal data concerning you for direct marketing purposes. You also have the right to object to processing based on Art. 6 (1) sentence 1 lit. e or f GDPR on grounds relating to your particular situation.

(2) We will then no longer process the personal data for direct marketing purposes and otherwise only process it if we can demonstrate compelling legitimate grounds which override your interests, rights, and freedoms, or if processing serves the establishment, exercise, or defense of legal claims.

23. Provision of Personal Data

The provision of personal data for the use of our online offering is neither legally nor contractually required. You are also not obliged to provide us with personal data within the scope of this online offering. However, for the conclusion of a contract with us, it is necessary that the user provides personal data that must subsequently be processed by us. Failure to provide the personal data would result in a contract not being concluded with the user.

24. Automated Decision-Making

No automated decision-making or profiling pursuant to Art. 22 GDPR is carried out by us.

25. Changes to the Privacy Policy

Users are requested to regularly inform themselves about the content of our privacy policy. We adapt the privacy policy as soon as changes in data processing carried out by us or changes in legal regulations make this necessary. We will inform you as soon as changes require your cooperation (e.g. consent) or other individual notification.