Privacy Policy
We are pleased that you are visiting our website and thank you for your interest. We would like to inform you here about the handling of your personal data when using this website.
1. Data protection at a glance
General notes
The following notes provide an overview of what happens to your personal data when you visit this website. Personal data in the sense of the GDPR (Art. 4 No. 1 GDPR) and the Swiss Federal Data Protection Act as amended ("DPA") is any data relating to an identified or identifiable natural person. This includes, for example, your name or e-mail address, but also the IP address with which you use our services. Insofar as you provide information about your visual acuity or other medical information required for the provision of corrective visual aids such as contact lenses in the context of using our services, this is health data in the sense of Art. 4 No. 15 DSGVO and the corresponding DSG provisions, which are particularly protected as personal data. For detailed information on the subject of data protection, please refer to our privacy policy listed below this text.
Data collection on this website
Who is responsible for the data collection on this website?
The website operator carries out the data processing on this website. You can find the contact details of the website operator in the section "Information about the responsible party" in this data protection declaration.
How do we collect your data?
On the one hand, your data is collected when you provide it to us. This can be, for example, data that you enter into a form.
Other data is collected automatically or after your consent when you visit the website by our IT systems. This is mainly technical data (e.g. internet browser, operating system or time of page view). The collection of this data takes place automatically as soon as you call up this website.
What do we use your data for?
Part of the data is collected to ensure error-free provision of the website. Other data may be used to analyze your usage behavior.
What rights do you have regarding your data?You have the right at any time to receive information free of charge about the origin, recipient and purpose of your stored personal data. You also have a right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
You can contact us at any time with regard to this and other questions on the subject of data protection.
Third-party analytics and tools
When visiting this website, your surfing behavior can be statistically evaluated. This is done mainly with so-called analysis programs.
Detailed information about these analysis programs can be found in the following privacy policy.
2. Hosting & Content Delivery Network (CDN)
Hosting
This website is hosted externally. The personal data collected on this website is stored on the hoster's servers. This may include, but is not limited to, IP addresses, contact requests, meta and communication data, contractual data, contact details, names, website accesses and other data generated via a website.
The external hosting is carried out for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 para. 1 lit. b DSGVO and the corresponding DSG provisions) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f DSGVO and the corresponding DSG provisions). If a corresponding consent was requested, the processing is based exclusively on Art. 6 para. 1 lit. a DSGVO and the corresponding DSG provisions. The consent can be revoked at any time.
Our hoster will only process your data to the extent necessary to fulfill its service obligations and will follow our instructions regarding this data.
We use the following hoster:
OVH Groupe SA
Lille
Handelsregister 537 407 926
Rue Kellermann 2
59100 Roubaix
France
For more information about the hoster's privacy policy, please visit the following website: https://www.ovhcloud.com/en-gb/personal-data-protection/
CDN
We use the service "Cloudflare" via our hoster. The provider is Cloudflare Inc, 101 Townsend St., San Francisco, CA 94107, USA (hereinafter "Cloudflare").
Cloudflare offers a globally distributed content delivery network with DNS. This technically routes the transfer of information between your browser and our website through Cloudflare's network. This enables Cloudflare to analyze traffic between your browser and our website and serve as a filter between our servers and potentially malicious traffic from the Internet. In doing so, Cloudflare may also use cookies or other technologies to recognize Internet users, but these are used solely for the purpose described here.
The use of Cloudflare is based on the legitimate interest in providing our website as error-free and secure as possible (Art. 6 para. 1 lit. f DSGVO and the corresponding DSG provisions).
You can find more information about security and privacy at Cloudflare here: https://www.cloudflare.com/privacypolicy/.
Job processing
We have concluded an order processing contract with our hoster. This is a contract required by data protection law, which ensures that the hoster only processes the personal data of our website visitors in accordance with our instructions and in compliance with the DSGVO and the DSG.
3. General notes and mandatory information
Privacy
We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data are collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
We would like to point out that data transmission on the Internet (e.g. when communicating by e-mail) can have security gaps. A complete protection of the data against access by third parties is not possible.
Responsible entity, data protection officer
The responsible party for data processing on this website is:
Vision Group AG
Riedwiesenstrasse 23
8305 Dietlikon
SWITZERLAND
Phone: +41 43 55 07 333
E-mail: [email protected]
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, e-mail addresses, etc.). If you have any concerns regarding data protection, you can address them to our data protection officer at the following contact address: Data Protection Officer, Vision Group AG, Riedwiesenstrasse 23, 8305 Dietlikon, SWITZERLAND, or by e-mail to [email protected] with the subject "Data Protection".
Within the European Union we have the following branch:
Vision Group AG, Alt-Moabit 91b, 10559 Berlin
Storage duration
Unless a more specific storage period is mentioned within this privacy policy, your personal data will remain with us until the purpose for data processing ceases to apply. If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, the data will be deleted once these reasons no longer apply.
Note on data transfer to the USA and other countries abroad
Among other things, we use tools from companies based in the USA. If these tools are active, your personal data may be transferred to the US servers of the respective companies and processed there. We would like to point out that the USA is not a safe third country in the sense of EU data protection law and the DPA. For example, US companies are obliged to hand over personal data to security authorities without you as a data subject being able to take legal action against this. It can therefore not be ruled out that US authorities (e.g. intelligence services) process, evaluate and permanently store your data located on US servers for monitoring purposes. We have no influence on these processing activities. Furthermore, we transfer personal data to group companies and/or third parties such as our IT service providers, marketing service providers, programmers, etc. located in Germany, Lithuania and Poland. Where applicable, the necessary measures, such as the conclusion of EU standard contractual clauses, are implemented.
Revocation of your consent to data processing
Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to object to the collection of data in special cases and to direct marketing (Art. 21 DSGVO and the corresponding DSG provisions)
If the data processing is carried out on the basis of Art. 6 (1) lit. e or f DSGVO and the corresponding DSG provisions, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation; this also applies to profiling based on these provisions. The respective legal basis on which processing is based can be found in this privacy policy. If you object, we will no longer process your personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the purpose of asserting, exercising or defending legal claims (objection under Article 21(1) DSGVO and the corresponding DSG provisions).
If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling, insofar as it is associated with such direct marketing. If you object, your personal data will subsequently no longer be used for the purpose of direct marketing (objection pursuant to Art. 21 (2) DSGVO and the corresponding DSG provisions).
Right of complaint to the competent supervisory authority
In the event of violations of the GDPR and the FADP, the data subjects shall have a right of appeal to a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged violation. The right of appeal is without prejudice to other administrative or judicial remedies.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request that the data be transferred directly to another responsible party, this will only be done insofar as it is technically feasible.
Information, deletion and correction
Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipient and the purpose of data processing and, if necessary, a right to correction or deletion of this data. For this purpose, as well as for further questions on the subject of personal data, you can contact us at any time.
If you want your customer data to be deleted, please contact our customer support via email or phone.
E-Mail: [email protected]
Phone: +41 43 55 07 333
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. For this purpose, you can contact us at any time. The right to restriction of processing exists in the following cases:
If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the review, you have the right to request the restriction of the processing of your personal data.
If the processing of your personal data happened/is happening unlawfully, you may request the restriction of data processing instead of erasure.
If we no longer need your personal data, but you need it to exercise, defend or enforce legal claims, you have the right to request restriction of the processing of your personal data instead of deletion.
If you have lodged an objection pursuant to Art. 21 (1) DSGVO and the corresponding DSG provisions, a balancing of your and our interests must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data may - apart from being stored - only be processed with your consent or for the assertion, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of an important public interest of the European Union or a Member State and Switzerland.
4. Data collection on this website
Cookies
Our Internet pages use so-called "cookies". Cookies are text files which are saved on the user’s computer when they visit a website. We use so-called session cookies, which are immediately deleted when the browser is closed. These cookies enable, for example, the shopping cart to be being displayed on different webpages, so you can benefit from seeing how many items are currently in your shopping basket and what their current purchase value is.
In addition, we also use cookies which are stored after the session has ended (persistent cookies). These cookies in particular make our service more user friendly, efficient and secure. For example, thanks to these files it is possible for you to be shown information specifically tailored to your interests on the webpage. Their exclusive purpose is, therefore, to best tailor our service to your customer requirements and make surfing with us as simple as possible.
Cookies that are necessary to carry out the electronic communication process (necessary cookies) or to provide certain functions that you have requested (functional cookies, e.g. for the shopping cart function) or to optimize the website (e.g. cookies to measure the web audience) are stored on the basis of Art. 6 (1) lit. f DSGVO and the corresponding DSG provisions, unless another legal basis is specified. The website operator has a legitimate interest in storing cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies has been requested, the storage of the cookies in question is based exclusively on this consent (Art. 6 para. 1 lit. a DSGVO and the corresponding DSG provisions); consent can be revoked at any time.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. When deactivating cookies, the functionality of this website may be limited.
If cookies are used by third-party companies or for analysis purposes, we will inform you about this separately within the framework of this data protection declaration and, if necessary, request your consent.
Cookie consent with Usercentrics
Our website uses the cookie consent technology of Usercentrics to obtain your consent to the storage of certain cookies on your terminal device and to document this in accordance with data protection law. The provider of this technology is Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, website: https://usercentrics.com/de/ (hereinafter "Usercentrics").
When you visit our website, a connection is established to the servers of Usercentrics in order to obtain your consent and other declarations regarding the use of cookies. Usercentrics then stores a cookie in your browser in order to be able to assign the consents given to you or their revocation. The data collected in this way is stored until you request us to delete it, delete the Usercentrics cookie yourself or the purpose for storing the data no longer applies. Mandatory legal storage obligations remain unaffected.
Usercentrics is used to obtain the legally required consent for the use of cookies. The legal basis for this is Art. 6 para. 1 lit. c DSGVO and the corresponding DSG provisions.
Job processing
We have concluded a data processing contract with the above-mentioned provider. This is a contract required by data protection law, which ensures that this provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the DSGVO and the DSG.
Request by e-mail or phone
If you contact us by e-mail or telephone your inquiry including all resulting personal data (name, inquiry) will be stored and processed by us for the purpose of processing your request. We do not pass on this data without your consent.
The processing of this data is based on Art. 6 (1) lit. b DSGVO and the corresponding DSG provisions, if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the requests addressed to us (Art. 6 (1) (f) DSGVO and the corresponding DSG provisions) or on your consent (Art. 6 (1) (a) DSGVO and the corresponding DSG provisions), if this was requested.
The data you send to us via contact requests will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g. after your request has been processed). Mandatory legal provisions - in particular legal retention periods - remain unaffected.
Registration on this website
You can register on this website to use additional functions on the site. We use the data entered for this purpose only for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise we will reject the registration.
For important changes, for example in the scope of the offer or in the case of technically necessary changes, we use the e-mail address provided during registration to inform you in this way.
The data entered during registration is processed for the purpose of implementing the user relationship established by the registration and, if necessary, for initiating further contracts (Art. 6 para. 1 lit. b DSGVO and the corresponding DSG provisions).
We will store the data collected during registration as long as you are registered on this website and will be deleted afterwards. Legal retention periods remain unaffected.
5. analysis tools and marketing
Google Analytics
This website uses Google Analytics, a web analysis service of Google Inc. ("Google"). Google Analytics uses so-called "cookies", text files, which are stored on your computer and enable your use of the website to be analysed. The information about your use of this website generated by the cookies is usually transferred to a Google server in the USA where it is stored. In the event that IP-anonymisation is activated on this website, your IP address will, however, be shortened first by Google within member states of the European Union or in other contracting states of the agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. Google will use this information on behalf of the operator of this website, in order to analyse your use of the website, to compile reports on the website activities and to provide other services associated with the website use and internet use to the website operator.
The IP address transmitted from your browser within the scope of Google Analytics is not merged with other Google data. You can prevent the storage of cookies by making a corresponding setting in your browser software; however, we would like to point out that in this case you may not be able to make full use of all functions of this website. You can also prevent the recording of the data generated by the cookie and related to your use of the website (incl. your IP address) and its transmission to Google as well as the processing of this data by Google, by downloading and installing the browser plugin available under the following link: browser plugin (http://tools.google.com/dlpage/gaoptout?hl=de).
The website uses re-marketing with Google Analytics for online advertising. Our adverts are posted on the websites of third-party service providers (including Google). Both we and third-party service providers (including Google) use first-party cookies (e.g. Google Analytics cookies) and third-party cookies (e.g. DoubleClick cookies) together in order to post, adjust and optimise adverts based on your previous visits to our website. The website uses Google Analytics performance reports per demographic characteristics and interests. We use data obtained by Google through interest-based advertising and the visitor data of third-party service providers (e.g. age, sex and interests) in Google Analytics for trend analyses and marketing purposes.
IP anonymization
We have activated the IP anonymization function on this website. This means that your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.
Browser plugin
You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
For more information on how Google Analytics handles user data, please see Google's privacy policy:
https://support.google.com/analytics/answer/6004245?hl=de.
Job processing
We have concluded an order processing contract with Google.
Demographic characteristics in Google Analytics
This website uses the "demographic characteristics" function of Google Analytics to display suitable advertisements to website visitors within the Google advertising network. This allows reports to be generated that contain statements about the age, gender and interests of site visitors. This data comes from interest-based advertising from Google as well as from visitor data from third-party providers. This data cannot be assigned to a specific person. You can deactivate this function at any time via the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as shown in the item "Objection to data collection".
Google Analytics E-commerce Tracking
This website uses the "e-commerce tracking" function of Google Analytics. With the help of e-commerce tracking, the website operator can analyze the purchasing behavior of website visitors to improve its online marketing campaigns. This involves recording information such as orders placed, average order values, shipping costs and the time from viewing to purchasing a product. This data can be summarized by Google under a transaction ID, which is assigned to the respective user or his device.
Storage duration
Data stored by Google at user and event level that is linked to cookies, user identifiers (e.g. User ID) or advertising IDs (e.g. DoubleClick cookies, Android advertising ID) is anonymized or deleted after 14 months. For details, please see the following link: https://support.google.com/analytics/answer/7667196?hl=de
Google Ads
The website operator uses Google Ads. Google Ads is an online advertising program of Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads enables us to display advertisements in the Google search engine or on third-party websites when the user enters certain search terms on Google (keyword targeting). Furthermore, targeted advertisements can be played on the basis of user data available at Google (e.g. location data and interests) (target group targeting). As the website operator, we can evaluate this data quantitatively by analyzing, for example, which search terms led to the display of our advertisements and how many ads resulted in corresponding clicks.
The use of Google Ads is based on Art. 6 para. 1 lit. f DSGVO and the corresponding DSG provisions. The website operator has a legitimate interest in marketing its services and products as effectively as possible.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://policies.google.com/privacy/frameworks and https://privacy.google.com/businesses/controllerterms/mccs/.
Google Remarketing
This website uses the functions of Google Analytics Remarketing. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Remarketing analyzes your user behavior on our website (e.g. clicking on certain products) in order to classify you in certain advertising target groups and subsequently play suitable advertising messages to you when you visit other online offers (remarketing or retargeting).
Furthermore, the advertising target groups created with Google Remarketing can be linked with Google's cross-device functions. In this way, interest-based, personalized advertising messages that have been adapted to you depending on your previous usage and surfing behavior on one end device (e.g. cell phone) can also be displayed on another of your end devices (e.g. tablet or PC).
If you have a Google account, you can object to personalized advertising at the following link: https://www.google.com/settings/ads/onweb/.
The use of Google Remarketing is based on Art. 6 para. 1 lit. f DSGVO and the corresponding DSG provisions. The website operator has a legitimate interest in marketing its products as effectively as possible. If a corresponding consent was requested, the processing is based exclusively on Art. 6 para. 1 lit. a DSGVO and the corresponding DSG provisions; the consent can be revoked at any time.
For more information and the privacy policy, please see Google's privacy policy at: https://policies.google.com/technologies/ads?hl=de.
Target group formation with customer matching
To create target groups, we use, among other things, Google Remarketing's customer matching. In this process, we transfer certain customer data (e.g., e-mail addresses) from our customer lists to Google. If the customers in question are Google users and logged into their Google account, they are shown matching advertising messages within the Google network (e.g. on YouTube, Gmail or in the search engine).
Google Conversion Tracking
This website uses Google Conversion Tracking. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
With the help of Google conversion tracking, Google and we can recognize whether the user has performed certain actions. For example, we can evaluate which buttons on our website were clicked how often and which products were viewed or purchased particularly frequently. This information is used to create conversion statistics. We learn the total number of users who clicked on our ads and what actions they took. We do not receive any information with which we can personally identify the user. Google itself uses cookies or comparable recognition technologies for identification.
The use of Google conversion tracking is based on Art. 6 (1) lit. f DSGVO and the corresponding DSG provisions. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising. If a corresponding consent was requested (e.g. consent to store cookies), the processing is based exclusively on Art. 6 para. 1 lit. a DSGVO and the corresponding DSG provisions; the consent can be revoked at any time.
For more information on Google conversion tracking, please see Google's privacy policy: https://policies.google.com/privacy?hl=de.
Google DoubleClick
This website uses functions of Google DoubleClick. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter "DoubleClick").
DoubleClick is used to show you interest-based advertisements throughout the Google advertising network. The advertisements can be targeted to the interests of the respective viewer with the help of DoubleClick. For example, our ads may be displayed in Google search results or in banner ads associated with DoubleClick.
In order to be able to display interest-based advertising to users, DoubleClick must be able to recognize the respective viewer and associate the web pages visited, clicks and other information on user behavior with them. For this purpose, DoubleClick uses cookies or comparable recognition technologies (e.g. device fingerprinting). The information collected is combined into a pseudonymous user profile in order to display interest-based advertising to the relevant user.
Google DoubleClick is used in the interest of targeted advertising measures. This represents a legitimate interest within the meaning of Art. 6 (1) f DSGVO and the corresponding DSG provisions. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a DSGVO and the corresponding DSG provisions; the consent can be revoked at any time.
For further information on how to object to the advertisements displayed by Google, please refer to the following links: https://policies.google.com/technologies/ads and https://adssettings.google.com/authenticated.
Facebook Pixel
This website uses the visitor action pixel from Facebook for conversion measurement. The provider of this service is Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the data collected is also transferred to the USA and other third countries.
This allows the behavior of page visitors to be tracked after they have been redirected to the provider's website by clicking on a Facebook ad. This allows the effectiveness of the Facebook ads to be evaluated for statistical and market research purposes and future advertising measures to be optimized.
The collected data is anonymous for us as the operator of this website, we cannot draw any conclusions about the identity of the users. However, the data is stored and processed by Facebook, so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes, according to the Facebook data usage policy. This allows Facebook to enable the placement of advertisements on Facebook pages as well as outside of Facebook. This use of the data cannot be influenced by us as the site operator.
The use of Facebook Pixel is based on Art. 6 para. 1 lit. f DSGVO and the corresponding DSG provisions. The website operator has a legitimate interest in effective advertising measures including social media. If a corresponding consent has been requested (e.g. consent to store cookies), the processing is based exclusively on Art. 6 Para. 1 lit. a DSGVO and the corresponding DSG provisions; the consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Facebook Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 DSGVO). The joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook. The processing by Facebook that takes place after the onward transfer is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in a joint processing agreement. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the privacy information when using the Facebook tool and for the privacy-secure implementation of the tool on our website. Facebook is responsible for the data security of Facebook products. You can assert data subject rights (e.g., requests for information) regarding data processed by Facebook directly with Facebook. If you assert the data subject rights with us, we are obliged to forward them to Facebook.
You can find more information about protecting your privacy in Facebook's privacy policy: https://de-de.facebook.com/about/privacy/.
You can also disable the Custom Audiences remarketing feature in the Ad Settings section at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. To do this, you must be logged in to Facebook.
If you do not have a Facebook account, you can disable usage-based advertising from Facebook on the European Interactive Digital Advertising Alliance website: http://www.youronlinechoices.com/de/praferenzmanagement/.
Criteo
This website uses functions of Criteo. The provider is Criteo SA, 32 Rue Blanche, 75009 Paris, France (hereinafter "Criteo").
Criteo is used to show you interest-based ads within the Criteo ad network. Your interests are determined on the basis of your previous usage behavior. Here, Criteo records, for example, which products you have viewed, added to your shopping cart or purchased. You can find more details about the data collected by Criteo here: https://www.criteo.com/de/privacy/how-we-use-your-data/.
In order to show you interest-based advertising, we or other Criteo partners must be able to recognize you. For this purpose, a cookie is stored on your end device or a comparable identifier is used that links your user behavior with a pseudonymous user profile. For details, please refer to Criteo's privacy policy at: https://www.criteo.com/de/privacy/.
Your personal data and the Criteo cookies stored in your browser are stored for a maximum of 13 months from the date of collection.
Criteo is used in the interest of targeted advertising measures. This represents a legitimate interest within the meaning of Art. 6 (1) f DSGVO and the corresponding DSG provisions. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a DSGVO and the corresponding DSG provisions; the consent can be revoked at any time.
Criteo and we are joint controllers within the meaning of Art. 26 DSGVO. An agreement on joint processing has been concluded between Criteo and us, the main contents of which Criteo describes under the following link: https://www.criteo.com/de/privacy/how-we-use-your-data/.
Coupon Marketing
In order to select a voucher offer that is currently of interest to you, we transmit the hash value of your e-mail address and your IP address to Sovendus GmbH, Hermann-Veit-Str. 6, 76135 Karlsruhe (Sovendus) in pseudonymized and encrypted form (Art. 6 para.1 f DSGVO). The pseudonymized hash value of the e-mail address is used by Sovendus to take into account any objection to advertising (Art. 21 para.3, Art. 6 para.1 c DSGVO). The IP address is used by Sovendus exclusively for data security purposes and is usually anonymized after seven days (Art. 6 para.1 f DSGVO). In addition, for billing purposes, we transmit pseudonymized order number, order value with currency, session ID, coupon code and time stamp to Sovendus (Art. 6 para.1 f DSGVO). If you are interested in a voucher offer from Sovendus, there is no advertising objection to your email address and you click on the voucher banner that is only displayed in this case, we transmit your title, name, zip code, country and email address in encrypted form to Sovendus for the preparation of the voucher (Art. 6 para.1 b, f DSGVO and the corresponding DSG provisions).
For further information on the processing of your data by Sovendus, please refer to the online privacy notices at https://www.sovendus.de/datenschutz.
Trusted Shops Trustbadge
To display our Trusted Shops seal of approval and to offer Trusted Shops membership to buyers after an order, the Trusted Shops trust badge is integrated on this website.
This serves to protect our legitimate interests in an optimal marketing of our offer, which prevail in the context of a balancing of interests, Art. 6 para. 1 lit. f DSGVO and the corresponding DSG provisions. The Trustbadge and the services advertised with it are an offer of Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne.
When the Trustbadge is called up, the web server automatically saves a so-called server log file, which contains, for example, your IP address, the date and time of the call-up, the amount of data transferred and the requesting provider (access data) and documents the call-up. This access data is not evaluated and is automatically overwritten at the latest seven days after the end of your visit to the site.
Further personal data will only be transferred to Trusted Shops if you decide to use Trusted Shops products after completing an order or have already registered to use them. In this case, the contractual agreement between you and Trusted Shops applies.
6. Newsletter
Newsletter data
If you would like to receive the newsletter offered on the website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the specified e-mail address and agree to receive the newsletter. Further data is not collected or only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.
The processing of the data entered in the newsletter registration form is based exclusively on your consent (Art. 6 para. 1 lit. a DSGVO and the corresponding DSG provisions). You can revoke your consent to the storage of the data, the e-mail address and their use for sending the newsletter at any time, for example via the "unsubscribe" link in the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation.
The data you provide for the purpose of receiving the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after unsubscribing from the newsletter or after the purpose has ceased to exist. We reserve the right to delete or block e-mail addresses from our newsletter distribution list at our own discretion within the scope of our legitimate interest according to Art. 6 Para. 1 lit. f DSGVO and the corresponding DSG provisions.
After you have unsubscribed from the newsletter distribution list, your e-mail address will be stored by us or the newsletter service provider in a blacklist, if necessary, in order to prevent future mailings. The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with the legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 Para. 1 lit. f DSGVO and the corresponding DSG provisions). The storage in the blacklist is not limited in time. You can object to the storage if your interests outweigh our legitimate interest.
Listmonk
This website uses the services of Listmonk for sending newsletters. Listmonk is a service with which, among other things, the sending of newsletters can be organized and analyzed.
Job processing
We have concluded an order processing contract with the above-mentioned provider. This is a contract required by data protection law, which ensures that this provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the DSGVO and the DSG.
7. Other plugins and tools
Google Web Fonts (local)
This site uses so-called web fonts provided by Google for the uniform display of fonts. The Google Fonts are installed locally. A connection to Google servers does not take place.
For more information about Google Web Fonts, please visit https://developers.google.com/fonts/faq and see Google's privacy policy: https://policies.google.com/privacy?hl=de.
Google Maps
This site uses the map service Google Maps. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
To use the functions of Google Maps, it is necessary to store your IP address. This information is usually transferred to a Google server in the USA and stored there. The provider of this site has no influence on this data transmission. If Google Maps is activated, Google may use Google Web Fonts for the purpose of uniform display of fonts. When calling up Google Maps, your browser loads the required web fonts into its browser cache in order to display texts and fonts correctly.
The use of Google Maps is in the interest of an appealing presentation of our online offers and an easy location of the places indicated by us on the website. This represents a legitimate interest within the meaning of Art. 6 para. 1 lit. f DSGVO and the corresponding DSG provisions. If a corresponding consent has been requested, the processing is based exclusively on Art. 6 para. 1 lit. a DSGVO and the corresponding DSG provisions; the consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.
You can find more information on the handling of user data in Google's privacy policy: https://policies.google.com/privacy?hl=de.
Google reCAPTCHA
We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on this website. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
The purpose of reCAPTCHA is to check whether the data entry on this website (e.g. in a contact form) is made by a human or by an automated program. For this purpose, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis begins automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g. IP address, time spent by the website visitor on the website or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run completely in the background. Website visitors are not notified that an analysis is taking place.
The storage and analysis of the data is based on Art. 6 para. 1 lit. f DSGVO and the corresponding DSG provisions. The website operator has a legitimate interest in protecting its web offers from abusive automated spying and from SPAM. If a corresponding consent was requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a DSGVO and the corresponding DSG provisions; the consent can be revoked at any time.
For more information about Google reCAPTCHA, please see the Google Privacy Policy and the Google Terms of Service at the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.
Dixa
We use the CRM system Dixa to process user requests. The provider is Dixa ApS, Vimmelskaftet 41A, 1st Sal., 1161 Copenhagen, Denmark.
We use Dixa to be able to process your requests quickly and efficiently. This represents a legitimate interest within the meaning of Art. 6 para. 1 lit. f DSGVO and the corresponding DSG provisions.
You can send requests only with the e-mail address and without giving your name.
The messages sent to us remain with us until you request us to delete them or the purpose for storing the data no longer applies (e.g. after processing your request has been completed). Mandatory legal provisions - in particular retention periods - remain unaffected.
If you are not comfortable with us processing your request through Dixa, you may alternatively communicate with us by email or phone.
For more information, please see Dixa's privacy policy: https://www.dixa.com/legal/privacy/.
Job processing
We have concluded an order processing contract with the above-mentioned provider. This is a contract required by data protection law, which ensures that this provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the DSGVO and the DSG.
8. ECommerce and payment providers
Processing of data (customer and contract data)
We collect, process and use personal data only to the extent that they are necessary for the establishment, content or modification of the legal relationship (inventory data). This is done on the basis of Art. 6 (1) lit. b DSGVO and the corresponding DSG provisions, which permits the processing of data for the fulfillment of a contract or pre-contractual measures. Insofar as health data is required for this purpose, the legal basis is Art. 9 (2) h DSGVO and the corresponding DSG provisions. We collect, process and use personal data about the use of this website (usage data) only to the extent necessary to enable the user to use the service or to bill the user.
The collected customer data will be deleted after completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.
Data transmission at the conclusion of a contract for online stores, merchants and shipment of goods
We transmit personal data to third parties only if this is necessary within the scope of the contract processing, for example to the companies entrusted with the delivery of the goods or the credit institution entrusted with the payment processing. A further transmission of the data does not take place or only if you have expressly agreed to the transmission. Your data will not be passed on to third parties without your express consent, for example for advertising purposes.
The basis for the data processing is Art. 6 para. 1 lit. b DSGVO and the corresponding DSG provisions, which allows the processing of data for the fulfillment of a contract or pre-contractual measures.
In order to process your order, we work together with the following service providers, who support us in whole or in part in the execution of concluded contracts. Personal data is transmitted to these service providers in accordance with the following information.
Use of special service providers for order processing and handling
Paqato
In order to enable the customer to track his shipment after placing the order, we use the service of PAQATO GmbH, Johann-Krane-Weg 6, 48149 Münster ("Paqato").
On our behalf, Paqato sends shipping notifications and status updates on the delivery. For this purpose, in accordance with Art. 6 (1) f DSGVO and the corresponding DSG provisions, we pass on certain customer data (email address, first and last name and address) together with the shipment number to Paqato on the basis of our legitimate interest in effective and informative customer communication as well as transparent and reliable shipment processing, which is also in the customer's interest, after the package has been posted.
The data will not be passed on to third parties by Paqato and will be processed exclusively for the purpose named above. After completed shipping, the data will be deleted by Paqato.
We have entered into an order processing agreement with Paqato, by which we oblige Paqato to protect the data of our customers in accordance with the legal requirements.
Paqato's privacy policy can be viewed here: https://www.paqato.com/datenschutzerklaerung/
pixi
The order is processed by the service provider "pixi" (Descartes Systems (Germany) GmbH, Walter-Gropius-Str. 15, D-80807 Munich). Name, address and, if applicable, other personal data will be passed on to pixi in accordance with Art. 6 Para. 1 lit. b DSGVO and the corresponding DSG provisions exclusively for the purpose of processing the online order. Your data will only be passed on to the extent that this is actually necessary for the processing of the order. Details on pixi's data protection and the privacy policy of Descartes Systems (Germany) GmbH can be viewed at the following link: https://www.pixi.eu/datenschutz
Credit checks
In the case of a purchase on account or any other payment method for which we make advance payments, we may perform a credit check (scoring). For this purpose, we transmit your entered data (e.g. name, address, age or bank data) to a credit agency. Based on this data, the probability of a payment default is determined. If the risk of non-payment is excessive, we may refuse the payment method in question.
The credit assessment is carried out for the fulfillment of the contract (Art. 6 para. 1 lit. b DSGVO and the corresponding DSG provisions) and to avoid payment defaults (legitimate interest according to Art. 6 para. 1 lit. f DSGVO). If consent has been obtained, the credit assessment is based on this consent (Art. 6 (1) lit. DSGVO and the corresponding DSG provisions); consent can be revoked at any time.
Payment services
We integrate payment services from third-party companies on our website. When you make a purchase from us, your payment data (e.g. name, payment amount, account details, credit card number) is processed by the payment service provider for the purpose of processing the payment. For these transactions, the respective contract and data protection provisions of the respective providers apply. The payment service providers are used on the basis of Art. 6 para. 1 lit. b DSGVO (contract processing) and the corresponding DSG provisions, as well as in the interest of a smooth, convenient and secure payment process (Art. 6 para. 1 lit. f DSGVO and the corresponding DSG provisions). Insofar as your consent is requested for certain actions, Art. 6 para. 1 lit. a DSGVO and the corresponding DSG provisions are the legal basis for data processing; consents can be revoked at any time for the future.
Collection service provider
If you do not pay outstanding invoices despite repeated reminders, we reserve the right to transmit the data required for the execution of a debt collection to a collection service provider.
In addition, we may sell outstanding receivables to a collection service provider and, for this purpose, assign these receivables to a collection service provider, which in turn may enforce them against you in its own name under its own responsibility within the scope of statutory provisions.
The legal basis for the transmission of data within the scope of the trust collection is Art. 6 para. 1 lit. b DSGVO and the corresponding DSG provisions; the transmission of data within the scope of the sale of receivables is based on Art. 6 para. 1 lit. f DSGVO and the corresponding DSG provisions.
In Switzerland, we work with the following collection service providers:
Intrum AG
Eschenstrasse 12
8603 Schwerzenbach
9. Encryption
SSL or TLS encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or requests that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Encrypted payment transactions on this website
If, after the conclusion of a contract with costs, there is an obligation to provide us with your payment data (e.g. account number in the case of direct debit authorization), this data is required for payment processing.
Payment transactions via the common means of payment (Visa/MasterCard, direct debit) are made exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
With encrypted communication, your payment data that you transmit to us cannot be read by third parties.
10. Online presence in social networks
Data processing through social networks
We maintain publicly accessible profiles on social networks. The social networks used by us in detail can be found below.
Social networks such as Facebook, Twitter, etc. can generally analyze your user behavior extensively when you visit their website or a website with integrated social media content (e.g. like buttons or advertising banners). Visiting our social media presences triggers numerous processing operations relevant to data protection. In detail:
If you are logged into your social media account and visit our social media presence, the operator of the social media portal can assign this visit to your user account. However, your personal data may also be collected under certain circumstances if you are not logged in or do not have an account with the respective social media portal. In this case, this data collection takes place, for example, via cookies that are stored on your end device or by recording your IP address.
With the help of the data collected in this way, the operators of the social media portals can create user profiles in which your preferences and interests are stored. In this way, interest-based advertising can be displayed to you inside and outside the respective social media presence. If you have an account with the respective social network, the interest-based advertising can be displayed on all devices on which you are or were logged in.
Please also note that we cannot track all processing operations on the social media portals. Depending on the provider, further processing operations may therefore be carried out by the operators of the social media portals. For details, please refer to the terms of use and data protection provisions of the respective social media portals.
Legal basis
Our social media presences are intended to ensure the most comprehensive presence possible on the Internet. This is a legitimate interest within the meaning of Art. 6 (1) f DSGVO and the corresponding DSG provisions. The analysis processes initiated by the social networks may be based on different legal bases, which are to be specified by the operators of the social networks (e.g. consent within the meaning of Art. 6 Para. 1 lit. a DSGVO and the corresponding DSG provisions).
Responsible person and assertion of rights
If you visit one of our social media sites (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered during this visit. In principle, you can assert your rights (information, correction, deletion, restriction of processing, data portability and complaint) both against us and against the operator of the respective social media portal (e.g. against Facebook).
Please note that despite the joint responsibility with the social media portal operators, we do not have full influence on the data processing operations of the social media portals. Our options are largely determined by the corporate policy of the respective provider.
Storage duration
The data collected directly by us via the social media presence will be deleted from our systems as soon as you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies. Stored cookies remain on your terminal device until you delete them. Mandatory legal provisions - in particular retention periods - remain unaffected.
We have no influence on the storage period of your data, which is stored by the operators of the social networks for their own purposes. For details, please contact the operators of the social networks directly (e.g. in their privacy policy, see below).
Facebook
We have a profile on Facebook. The provider of this service is Facebook Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. According to Facebook, the collected data is also transferred to the USA and other third countries.
We have entered into a joint processing agreement (Controller Addendum) with Facebook. This agreement specifies the data processing operations for which we or Facebook is responsible when you visit our Facebook page. You can view this agreement at the following link: https://www.facebook.com/legal/terms/page_controller_addendum.
You can adjust your advertising settings independently in your user account. To do so, click on the following link and log in: https://www.facebook.com/settings?tab=ads.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.
For further details, please refer to Facebook's privacy policy: https://www.facebook.com/about/privacy/.