Data protection for www.flyfishing-salza.com

  1. Privacy Policy
    1. Introduction
    Protecting your personal data is a top priority. This privacy policy explains the nature, scope, and purpose of the processing of personal data (hereinafter referred to as “data”) in connection with the online service. This includes the associated website, functions, and content, as well as external online presences such as social media profiles (hereinafter collectively referred to as the “online service”). Your personal data is treated confidentially, and strict compliance with statutory data protection regulations and the provisions of this privacy policy is ensured.General InformationThis privacy policy provides a comprehensive overview of what happens to your personal data when you visit this website. Personal data comprises any information that can be used to personally identify you. Please refer to this complete privacy policy for detailed information regarding data protection.Controller

    Data processing on this website is carried out by the website operator. You can find the controller’s contact details in the “Controller” section of this privacy policy.

    Collection of Your Data

    Personal data is collected, on the one hand, when you actively provide it—for example, by filling out a contact form. Other data is recorded automatically or with your consent by the controller’s IT systems when you visit the website. This primarily involves technical data (e.g., internet browser, operating system, or the time the page was accessed). This data collection occurs automatically as soon as you enter the website.

    Use of Your Data

    Some data is collected to ensure the website functions correctly. Other data may be used to analyze your user behavior in order to optimize our services and tailor them to your needs.

    Data Transfer to External Parties

    As part of the data controller’s business operations, it may be necessary to transfer personal data to external parties. Such transfers occur only under specific conditions: if the transfer is necessary to fulfill a contract; if there is a legal obligation (e.g., to tax authorities); if there is a legitimate interest pursuant to Art. 6(1)(f) GDPR; or if another legal basis permits the transfer. When external service providers are used for data processing, personal data is transferred solely on the basis of a valid data processing agreement pursuant to Art. 28 GDPR. If data is processed jointly with other entities, a joint controllership agreement pursuant to Art. 26 GDPR is concluded.

    Withdrawal of Consent for Data Processing

    Certain data processing activities require your explicit consent. You may withdraw this consent at any time. The withdrawal of consent does not affect the lawfulness of data processing carried out prior to the withdrawal.

    Right to Object to Specific Data Processing and Advertising Measures (Art. 21 GDPR)

    If your personal data is processed based on Art. 6(1)(e) or (f) GDPR, you have the right to object to such processing at any time for reasons arising from your particular situation. This also applies to profiling based on these provisions. The specific legal basis for the data processing can be found in this privacy policy. In the event of an objection, the controller will no longer process your personal data unless compelling legitimate grounds can be demonstrated that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims (objection pursuant to Art. 21(1) GDPR).

     

    If your personal data is used for direct marketing purposes, you have the right to object to this processing at any time. This also applies to profiling, insofar as it is related to direct marketing. Following your objection, the controller will no longer use your personal data for these marketing purposes (objection pursuant to Art. 21(2) GDPR).

    Rights under the General Data Protection Regulation (GDPR)

    You have the right to lodge a complaint with a competent supervisory authority in the event of violations of the GDPR. This right may be exercised, in particular, in the Member State of your habitual residence, place of work, or the place of the alleged infringement. Other administrative or judicial remedies remain unaffected.

    Personal data processed by automated means based on consent or for the performance of a contract may be requested in a structured, commonly used, and machine-readable format. Upon request, this data may also be transmitted directly to another controller, provided this is technically feasible.

    Every data subject has the right to obtain information free of charge regarding their stored personal data, its origin, the recipients, and the purpose of the data processing. Furthermore, there is a right to the rectification or erasure of this data, subject to applicable legal provisions. You may contact the controller at any time regarding any further questions or concerns concerning personal data.

    You have the right to request the restriction of the processing of personal data if the accuracy of the data is contested and verification is pending. Restriction of processing may also be requested instead of erasure in cases of unlawful processing. Furthermore, restriction may be requested if the data is no longer required but is necessary for the establishment, exercise, or defense of legal claims. In the event of an objection to processing pursuant to Art. 21(1) GDPR, the right to restriction of processing also applies pending the determination of whose interests prevail.

    Where the processing of personal data has been restricted, such data may—with the exception of storage—only be processed with the data subject’s consent, for the establishment, exercise, or defense of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the EU or of a Member State.

    2. Controller

    The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

    Rudi Heger
    Address: Hauptstraße 4, 83313 Siegsdorf
    Website: www.flyfishing-salza.com
    E-mail: info@flyfishing-salza.com
    Telephone: +49 (0) 8662 7070

    3. Data Processors

    We work with various data processors who process data on our behalf. These service providers are contractually obliged to treat the data confidentially and to use it solely within the scope of the respective service provided. There are also instances where responsibility for data processing is shared with other entities. In such cases, responsibilities are clearly defined and documented to ensure compliance with data protection requirements.

    4. Definitions

    To ensure the transparency of this privacy policy and make it understandable to everyone, this policy primarily uses terms that are also defined in the General Data Protection Regulation (GDPR). The full legal definitions can be found in Art. 4 GDPR. The key terms relevant to this privacy policy are explained below:

    Personal data: This includes all information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). A person is considered identifiable if they can be identified, directly or indirectly—particularly by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., a cookie), or one or more specific factors expressing the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.

    Processing: This term encompasses any operation or set of operations performed on personal data, whether or not by automated means. This may include the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of data.

    Controller: This is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

    Processor: A natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.

    Consent: Any freely given, specific, informed, and unambiguous indication of the data subject’s wishes—by a statement or by a clear affirmative action—signifying agreement to the processing of personal data relating to them.

    Website: The website refers to the entire online offering provided by the controller under a specific URL. This includes all content, information, functions, and services published by the controller and made accessible to the user via this URL. The website serves as a digital platform for providing information and services, and for facilitating interaction between the controller and users.

    End device: An end device is an electronic device capable of accessing the Internet and loading web pages. Examples include computers, laptops, tablets, and smartphones.

    These definitions help to better understand the privacy policy and the meaning of the terms used.

    5. Hosting

    This website is hosted on the servers of an external service provider to ensure the reliable and secure use of this online service.

    Data processing by the hosting provider is carried out in accordance with Art. 6(1)(f) GDPR, as the controller has a legitimate interest in providing a stable and secure website. If it is necessary to obtain the user’s consent (for example, for the use of certain cookies or tracking technologies), data processing is based on the user’s consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TTDSG. You may revoke your consent at any time with effect for the future.

    The hosting provider is:

    maxcluster GmbH | Lise-Meitner-Straße 1b | D-33104 Paderborn

    Details regarding data processing and data protection can be found in the hosting provider’s privacy policy.
    You can find it here: https://maxcluster.de/datenschutz

    To ensure that your data is processed in compliance with applicable data protection regulations, a data processing agreement (DPA) has been concluded with the hosting provider. This agreement obliges the hosting provider to process the personal data of website visitors exclusively in accordance with the controller’s instructions and in compliance with the GDPR. The hosting provider guarantees comprehensive protection of your data through technical and organizational measures.

    6. Legal Basis for Data Processing

    The processing of your personal data is carried out based on the General Data Protection Regulation (GDPR) and other relevant legal provisions. Different legal bases apply depending on the purpose of the data processing.

    If you have consented to the processing of your personal data, such processing is based on your consent pursuant to Art. 6(1)(a) GDPR. This applies in particular to the processing of special categories of personal data pursuant to Art. 9(2)(a) GDPR and to the transfer of personal data to third countries pursuant to Art. 49(1)(a) GDPR. You may withdraw your consent at any time.

    The processing of your data may be necessary for the performance of a contract or to take steps prior to entering into a contract; in such cases, processing is based on Art. 6(1)(b) GDPR. Furthermore, processing may be necessary to comply with legal obligations, in which case it is carried out pursuant to Art. 6(1)(c) GDPR.

    In certain cases, processing is carried out to safeguard the legitimate interests of the controller or a third party, provided that your interests or fundamental rights and freedoms do not override them. Such processing is based on Art. 6(1)(f) GDPR.

    For certain processing activities, national regulations—such as Section 25 of the TTDSG regarding the storage of cookies or access to information on your end device—may also apply. The applicable legal bases are explained in detail in the specific sections of this privacy policy.

    Where your data is required for the performance of a contract or to take steps prior to entering into a contract, the processing of your data is based on Art. 6(1)(b) GDPR. Data processing for compliance with a legal obligation is based on Art. 6(1)(c) GDPR. Additionally, data processing may be carried out based on legitimate interests pursuant to Art. 6(1)(f) GDPR. The specific legal bases applicable in each individual case are explained in the following sections of this privacy policy.

    7. Data transfer to unsafe third countries and US companies not certified under the DPF

    If tools from companies based in third countries deemed unsafe under data protection law—or US tools provided by vendors not certified under the EU-US Data Privacy Framework (DPF)—are used on this website, your personal data may be transferred to and processed in those countries. Please note that it is not possible to guarantee a level of data protection equivalent to that of the EU in third countries considered unsafe under data protection law. In principle, the USA, as an unsafe third country, does not guarantee a level of data protection comparable to that of the EU. Consequently, data transfer to the USA is permitted only if the recipient is either certified under the “EU-US Data Privacy Framework” (DPF) or has implemented appropriate additional safeguards. Detailed information regarding potential transfers to third countries, including the data recipients, can be found in this privacy policy.

    8. Retention Period

    Unless a specific retention period is stated in this privacy policy, personal data will be retained by the controller until the purpose for data processing no longer applies. If a valid request for deletion is made or consent to data processing is withdrawn, the data in question will be deleted, provided there are no other legally permissible grounds for retaining the personal data (e.g., statutory retention periods under tax or commercial law). In such cases, deletion will take place once these grounds no longer apply.

    The controller retains personal data only for as long as is necessary to fulfill the specific purposes for which the data were collected. This includes, in particular, the fulfillment of contractual obligations, compliance with statutory retention periods, and the safeguarding of the controller’s legitimate interests, such as IT security and protection against misuse. If the processing of personal data is based on consent, the data will be retained until the data subject withdraws that consent. Such withdrawal is possible at any time with effect for the future. Thereafter, the data will be deleted without undue delay, unless statutory retention obligations or other overriding legal grounds necessitate continued storage.

    In summary, personal data are deleted once the purpose has been fulfilled or the legal basis for storage no longer applies, unless there are continuing legal obligations or legitimate interests justifying further storage.

    9. Security Measures and Data Minimization

    Comprehensive technical and organizational measures are implemented to effectively protect your personal data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access. Care is taken to ensure that only data strictly necessary for the respective purpose is collected and processed. This data minimization strategy helps to significantly reduce the risk of misuse and unauthorized access. Security measures are continuously updated in line with the state of the art to ensure a consistently high level of data protection.

    10. SSL/TLS Encryption

    To protect the security of your data during transmission, state-of-the-art encryption methods (e.g., SSL or TLS) are used via HTTPS. SSL (Secure Socket Layer) and TLS (Transport Layer Security) are protocols for encrypting data transmissions on the Internet. This ensures that data exchanged between your browser and the server is protected against unauthorized access. You can recognize an encrypted connection by the fact that the browser’s address bar changes from “http://” to “https://” and by the padlock symbol in the browser bar.

    11. Cookies

    This website uses cookies. These are small files that your browser automatically creates and that are stored on your device (laptop, tablet, smartphone, etc.) when you visit the site. Cookies do not damage your device and do not contain viruses, Trojans, or other malicious software.

    Information related to the specific device used is stored in the cookie. However, this does not mean that the controller thereby gains direct knowledge of your identity.

    On the one hand, cookies are used to make the use of the service more pleasant for you. For instance, the controller uses “session cookies” to recognize that you have already visited individual pages of the website. These are automatically deleted after you leave the site.

    Furthermore, the controller uses temporary cookies to optimize user-friendliness; these are stored on your device for a specific, defined period. If you visit the site again to use the services, the system automatically recognizes that you have been there before and recalls the inputs and settings you made, so you do not have to enter them again.

    On the other hand, the controller uses cookies to statistically record website usage and analyze it for the purpose of optimizing the service for you. These cookies enable the controller to automatically recognize that you have visited the site before. These cookies are automatically deleted after a defined period.

    The data processed via cookies is necessary for the aforementioned purposes to safeguard the legitimate interests of the controller and third parties pursuant to Art. 6 (1) sentence 1 lit. f GDPR.

    Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer or so that a notification appears before a new cookie is created. However, completely disabling cookies may result in you being unable to use all the functions of the website.

    12. Cookie Consent Banner

    This website uses a cookie consent banner to manage your consent for the use of cookies. The provider of this service is:

    Complianz BV
    Kalmarweg 14-5, 9723 JG, Groningen, Netherlands
    Further information regarding data processing can be found at: https://complianz.io/legal/

    Functionality and Purpose
    The cookie consent banner sets a technically necessary cookie to store your cookie consent choices. This cookie does not process personal data. It merely stores the settings you selected upon entering the website, including:

    a) Consent to or rejection of specific cookies
    b) Time of consent
    c) Duration of setting storage
    d) Legal basis for data processing

    Data processing via the cookie consent banner is carried out in accordance with Art. 6(1)(f) GDPR. The controller’s legitimate interest lies in ensuring lawful consent for the use of cookies. Where consent has been requested, processing is based on Art. 6(1)(a) GDPR.

    Storage Duration and Deletion
    The stored data remains saved until you manually delete the cookies in your browser or revoke your consent. You can change your settings at any time via the cookie settings on this website.

    13. Use of the contact form

    You may contact the controller regarding any questions via a form provided on this website. To identify the sender and respond to the inquiry, the following data must be provided: first name, last name, email address, and telephone number.

    Data processing for the purpose of contacting the controller is carried out in accordance with Art. 6(1)(a) GDPR, based on your voluntarily given consent.

    Personal data collected through the use of the contact form will be deleted once the inquiry has been resolved.

    14. Inquiries via email or telephone

    You may direct inquiries to the controller via email or telephone. Any personal data transmitted in this process (e.g., name, email address, telephone number, and the content of the inquiry itself) will be processed and stored by the controller exclusively for the purpose of handling the inquiry and addressing any follow-up questions.

    The legal basis for this data processing is Art. 6(1)(b) GDPR, as processing is necessary for the performance of a contract or to take steps prior to entering into a contract. If the processing is not related to a contract, it is based on Art. 6(1)(f) GDPR, as the controller has a legitimate interest in processing and responding to inquiries.

    15. Prohibition of Promotional Emails

    The use of contact details published in the legal notice for the purpose of sending unsolicited advertising and informational materials is hereby prohibited. Any unauthorized use of contact details for promotional purposes constitutes an infringement of the rights of the website operator and will not be tolerated. The website operator expressly reserves the right to take legal action in the event of violations, particularly regarding the unsolicited sending of promotional information such as spam emails.

    16. Newsletter

    If you wish to subscribe to the newsletter offered on the website, the controller requires a valid email address from you, as well as information allowing verification that you are the owner of the provided email address and consent to receiving the newsletter (double opt-in procedure). No further data is collected. This data is used exclusively for sending the requested information and is not disclosed to third parties.

    The processing of data entered into the newsletter registration form is based solely on your consent pursuant to Art. 6 (1) (a) GDPR. You may revoke your consent to the storage of the data and email address, as well as their use for sending the newsletter, at any time—for example, via the “unsubscribe” link in the newsletter or by sending a corresponding message to the controller. The lawfulness of data processing operations already carried out remains unaffected by the revocation.

    The data you provide for the purpose of receiving the newsletter will be stored until you unsubscribe from the newsletter and will be deleted after cancellation. Data stored by the controller for other purposes (e.g., email addresses for the member area) remains unaffected by this.

    Mailjet

    The newsletter is sent via the provider Mailjet. Mailjet is a service of Sinch Email, part of the Sinch Group, Lindhagensgatan 112, 112 51 Stockholm, Sweden. Newsletter recipients’ email addresses, as well as other data described in this notice, are stored on Mailjet’s servers within the EU. Mailjet uses this information to send and analyze the newsletters on behalf of the data controller. Additionally, according to its own statements, Mailjet may use this data to optimize or improve its own services—for example, for the technical optimization of newsletter delivery and display, or for business purposes such as determining the recipients’ countries of origin. However, Mailjet does not use newsletter recipients’ data to contact them directly or pass the data on to third parties.

    Mailjet SAS is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the USA. Any company certified under the DPF commits to adhering to these strict data protection standards. Further information on the EU-US DPF can be found at: https://www.dataprivacyframework.gov/.

    Further information regarding data protection at Mailjet can be found at: https://www.mailjet.com/de/rechtliches/sicherheit-datenschutz/.

    In addition, technical and organizational security measures are implemented to protect your personal data against manipulation, loss, destruction, or access by unauthorized persons. These security measures are continuously improved in line with technological developments.

    Sending newsletters to existing customers without consent

    Newsletters may be sent to existing customers without their express consent, provided certain conditions are met. This is permissible under Art. 6(1)(f) GDPR if the following conditions are fulfilled:

    a) Existing customer status: The customer provided their email address in connection with the sale of a good or service.
    b) Direct marketing for the company’s own similar products or services: The newsletter contains only advertising for the company’s own similar products or services.
    c) Notice regarding the right to object: The customer was clearly and explicitly informed—both when the email address was collected and in every newsletter—that they may object to the use of their email address at any time, incurring no costs other than the transmission costs at basic rates.
    d) No objection from the customer: The customer has not objected to the use of their email address.

    This type of newsletter distribution is based on the controller’s legitimate interest in informing existing customers about similar products or services and maintaining the business relationship. Data processing is carried out in accordance with Art. 6(1)(f) GDPR. Naturally, customers may object to the use of their email address for this purpose at any time. To do so, a simple email notification to the controller or the use of the “unsubscribe” link in the respective newsletter is sufficient.

    17. Use of analysis and tracking tools

    Analysis and tracking tools are used to ensure the needs-based design and continuous optimization of this website. These measures help to statistically record usage of this website and thereby optimize the services offered to you. Data storage and analysis are based on Art. 6(1)(f) of the GDPR, as the provider has a legitimate interest in offering an appealing and functional website.

    If appropriate consent has been obtained, processing is additionally based on Art. 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, provided the consent covers the storage of cookies or access to information on the user’s end device (e.g., device fingerprinting). This consent may be revoked at any time.

    Google Ads Tracking

    Google Ads Tracking, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”), is used. Google Ads Tracking employs cookies to measure the effectiveness of advertising campaigns and to analyze your use of this website. Information regarding your use of this website generated by the cookie is generally transmitted to Google servers in the USA and stored there.

    Google is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the USA. Every company certified under the DPF commits to complying with these strict data protection standards. Further information on the EU-US DPF can be found at: https://www.dataprivacyframework.gov/.

    Further information on data protection regarding Google Ads Tracking can be found at: https://policies.google.com/privacy.

    Google Ads Remarketing

    We use Google Ads Remarketing, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Ads Remarketing uses cookies to display targeted advertising to users who have previously visited this website. This enables us to show visitors to this website relevant ads on other websites within the Google Display Network. Information regarding your use of this website, generated by the cookie, is generally transmitted to and stored on a Google server in the USA.

    Google is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the USA. Any company certified under the DPF commits to adhering to these strict data protection standards. Further information on the EU-US DPF can be found at: https://www.dataprivacyframework.gov/.

    Further information regarding data protection in connection with Google Ads Remarketing can be found at: https://policies.google.com/privacy.

    Google AdSense

    We use Google AdSense, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google AdSense uses cookies to display personalized advertising on this website and to analyze ad performance. Information regarding your use of this website, generated by the cookie, is generally transmitted to and stored on Google servers in the USA.

    Google is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the USA. Any company certified under the DPF commits to adhering to these strict data protection standards. Further information on the EU-US DPF can be found at: https://www.dataprivacyframework.gov.

    Further information regarding data protection in connection with Google AdSense can be found at: https://policies.google.com/privacy.

    Google Analytics

    We use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Analytics uses cookies to enable an analysis of your use of the website. The information generated by the cookie regarding your use of this website is generally transmitted to and stored on Google servers in the USA. However, by activating IP anonymization on this website, your IP address is first truncated by Google within the Member States of the European Union or in other states party to the Agreement on the European Economic Area.

    Google is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the USA. Every company certified under the DPF commits to complying with these strict data protection standards. Further information on the EU-US DPF can be found at: https://www.dataprivacyframework.gov.

    Further information on data protection regarding Google Analytics can be found at: https://policies.google.com/privacy.

    Google Conversion Tracking

    We use Google Conversion Tracking, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Conversion Tracking uses cookies to measure the effectiveness of advertisements and to analyze your use of this website. The information generated by the cookie regarding your use of this website is generally transmitted to and stored on Google servers in the USA.

    Google is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the USA. Every company certified under the DPF commits to complying with these strict data protection standards. Further information on the EU-US DPF can be found at: https://www.dataprivacyframework.gov.

    Further information on data protection regarding Google Conversion Tracking can be found at: https://policies.google.com/privacy.

    Google Tag Manager

    We use Google Tag Manager, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Tag Manager itself does not use cookies and does not collect personal data. The tool triggers other tags, which may in turn collect data. Google Tag Manager does not access this data.

    Google is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the USA. Further information on the EU-US DPF can be found at: https://www.dataprivacyframework.gov.

    Further information on data protection regarding Google Tag Manager can be found at: https://policies.google.com/privacy.

    Microsoft Advertising

    We use Microsoft Advertising, a service provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (“Microsoft”). Microsoft Advertising uses cookies and similar technologies to measure the effectiveness of advertising campaigns and to analyze user behavior on this website. Information regarding your use of this website, generated by the cookie, is generally transmitted to and stored on Microsoft servers in the USA.

    Microsoft is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the USA. Every company certified under the DPF commits to adhering to these strict data protection standards. Further information on the EU-US DPF can be found at: https://www.dataprivacyframework.gov/.

    Further information on data protection regarding Microsoft Advertising can be found at: https://privacy.microsoft.com/de-de/privacystatement.

    18. Social Media Plugins

    This section provides information regarding the integration and use of social media on this website. It includes details on data processing and your rights in connection with the use of social media plugins and their functions.

    Facebook

    This website contains plugins from the social network Facebook, operated by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. These plugins allow you to share and distribute content from this website on your Facebook profile. You can recognize the Facebook plugins by the Facebook logo or the “Like” button integrated into this website.

    When you visit a page on this website that contains a Facebook plugin, your browser establishes a direct connection to Facebook’s servers. The plugin content is transmitted directly from Facebook to your browser and embedded into the website. Through this integration, Facebook receives information that your browser has accessed the corresponding page of this website, even if you do not have a Facebook account or are not currently logged into Facebook. This information (including your IP address) is transmitted directly from your browser to a Facebook server in the USA and stored there.

    If you are logged into Facebook, Facebook can directly associate your visit to this website with your Facebook account. If you interact with the plugins—for example, by clicking the “Like” button or posting a comment—the corresponding information is also transmitted directly to a Facebook server and stored there. This information is also published on your Facebook profile and displayed to your Facebook friends.

    The use of Facebook plugins is based on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TTDSG, as consent is required for the use of cookies and other tracking technologies. Consent may be revoked at any time with effect for the future. To prevent Facebook from associating data collected via this website with your Facebook account, you must log out of Facebook before visiting this website.

    Personal data is transferred to the USA based on the EU Commission’s Standard Contractual Clauses. Further information on this can be found at: https://www.facebook.com/legal/EU_data_transfer_addendum.

    Meta Platforms Ireland Limited is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the USA. Any company certified under the DPF commits to complying with these strict data protection standards. Further information on the EU-US DPF can be found at: https://www.dataprivacyframework.gov/.

    Further information regarding data processing and usage by Facebook, as well as your related rights and privacy settings, can be found in Facebook’s Data Policy at: https://www.facebook.com/privacy/policy/.

    Instagram

    This website incorporates features of the Instagram service, operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Instagram plugins allow you to share and distribute content from this website on your Instagram profile. You can recognize these plugins by the Instagram logo integrated into the website.

    When you visit a page on this website that contains an Instagram plugin, your browser establishes a direct connection to Instagram’s servers. The plugin content is transmitted directly from Instagram to your browser and integrated into the website. Through this integration, Instagram receives information that your browser has accessed the corresponding page of this website, even if you do not have an Instagram account or are not currently logged into Instagram. This information (including your IP address) is transmitted directly from your browser to an Instagram server in the USA and stored there.

    If you are logged into Instagram, Instagram can directly associate your visit to this website with your Instagram account. If you interact with the plugins—for example, by clicking the “Like” button or posting a comment—that information is also transmitted directly to an Instagram server and stored there. Furthermore, the information is published on your Instagram profile and displayed to your Instagram followers.

    Instagram plugins are used based on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TTDSG, as consent is required for the use of cookies and other tracking technologies. You may revoke your consent at any time with effect for the future. To prevent Instagram from associating data collected via this website with your Instagram account, you must log out of Instagram before visiting this website.

    Personal data is transferred to the USA based on the EU Commission’s Standard Contractual Clauses. Further information on this can be found at: https://www.facebook.com/legal/EU_data_transfer_addendum.

    Meta Platforms Ireland Limited is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the USA. Any company certified under the DPF commits to complying with these strict data protection standards. Further information on the EU-US DPF can be found at: https://www.dataprivacyframework.gov/.

    For further information regarding data processing and usage by Instagram, as well as your rights and privacy settings in this regard, please consult Instagram’s privacy policy at: https://help.instagram.com/155833707900388.

    19. Form Tools

    Here you will find information regarding the use of form tools on this website, including details on the processing of personal data and your rights in connection with the use of these forms.

    These tools are used based on legitimate interests pursuant to Art. 6(1)(f) GDPR to ensure efficient data collection and management. Where necessary, data processing is based on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TTDSG. Consent may be revoked at any time with effect for the future.

    20. Processing of Customer and Contract Data

    Personal customer and contract data are collected, processed, and used for the purpose of establishing, structuring, and modifying contractual relationships. This may include names, addresses, email addresses, and telephone numbers. Such information is necessary to provide services and facilitate communication. Depending on the selected payment method, payment information—such as credit card details, bank account details, or information regarding other payment services—is also collected and used exclusively for the payment process.

    In addition, usage and order data are processed, including information regarding orders, services used, prices, and delivery details. Personal data concerning the use of this website (usage data) are collected, processed, and used only to the extent necessary to enable the user to utilize the service or to bill for it.

    The processing of personal data is based on various legal grounds. Pursuant to Art. 6(1)(b) GDPR, data processing takes place for the performance of a contract or to take steps prior to entering into a contract—for example, to process orders and provide services. Furthermore, processing occurs pursuant to Art. 6(1)(c) GDPR for compliance with legal obligations, including statutory retention requirements. Finally, processing takes place pursuant to Art. 6(1)(f) GDPR to safeguard legitimate interests, such as improving services and ensuring IT security.

    Collected customer data are deleted following the completion of the order or the termination of the business relationship and the expiration of any applicable statutory retention periods. Statutory retention periods remain unaffected.

    21. Third-Party Payment Services

    This website uses third-party payment services to ensure a secure and convenient payment option for you. When you make a purchase via the website, your payment data (e.g., name, payment amount, account details, credit card number) is processed directly by the respective payment service provider for the purpose of processing the payment. The terms and conditions and data protection policies of the relevant provider apply to this process.

    Your data is processed on the basis of Art. 6(1)(b) GDPR for the performance of the contract, as well as in the interest of a smooth, convenient, and secure payment process pursuant to Art. 6(1)(f) GDPR. Where your consent is required for specific actions, data processing is based on Art. 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future.

    PayPal

    You have the option to pay for your purchases via PayPal. PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. If you use PayPal, your payment information is collected and processed directly by PayPal.

    PayPal is certified under the EU-US Data Privacy Framework (DPF), which ensures adequate protection for the transfer of personal data from the EU to the USA. Any company certified under the DPF commits to adhering to these strict data protection standards. Further information on the EU-US DPF can be found at: www.dataprivacyframework.gov.

    Additional information regarding the processing of your personal data by PayPal can be found in the PayPal Privacy Statement at: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

    Payment Service – MOLLIE

    You have the option to pay for your purchases using the following payment service: MOLLIE BV, Keizersgracht 126, 1015 CW Amsterdam, Netherlands.
    Further information on data processing can be found at: https://www.mollie.com/

    22. Google Fonts

    This website uses Google Fonts. Google Fonts is a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This service enables the use of fonts provided by Google to enhance the visual design of this website.

    To ensure the protection of your data, Google Fonts are hosted locally on our own server. Consequently, no connection is established with Google’s servers, and your IP address is not transmitted to Google. Your data remains entirely on the controller’s server and is not shared with third parties.

    23. External Videos

    This website embeds external videos to provide you with multimedia content and an interactive user experience. These integrations are provided by third-party providers who may process personal data when you use their services.

    Your data is processed on the basis of Art. 6(1)(b) GDPR for the performance of the contract—specifically to provide the videos and associated services—and based on the legitimate interest in ensuring a smooth, convenient, and secure user experience pursuant to Art. 6(1)(f) GDPR. Where your consent is required for specific actions, data processing is based on Art. 6(1)(a) GDPR. Consent may be revoked at any time with effect for the future.

    Vimeo

    Vimeo is used to embed videos on this website. Vimeo is a service provided by Vimeo Inc., 555 West 18th Street, New York, NY 10011, USA. When you visit a page containing Vimeo videos, a connection to Vimeo’s servers is established. Information regarding your use of this website, including your IP address, is transmitted to and stored by Vimeo.

    Vimeo is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the USA. Further information on the EU-US DPF can be found at: https://www.dataprivacyframework.gov.

    For more information on how Vimeo processes your personal data, please refer to the Vimeo privacy policy: https://vimeo.com/privacy.

    YouTube

    YouTube is used to embed videos on this website. YouTube is a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you visit a page containing YouTube videos, a connection to YouTube’s servers is established. Information regarding your use of this website, including your IP address, is transmitted to and stored by YouTube.

    Google is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the USA. Further information on the EU-US DPF can be found at: https://www.dataprivacyframework.gov.

    For more information on how YouTube processes your personal data, please refer to the YouTube privacy policy: https://policies.google.com/privacy.

    24. Map Service

    This website uses a map service to provide you with geographic information and an interactive user experience. This service is integrated via a third-party provider that may process personal data when you use the service.

    Your data is processed based on Art. 6(1)(b) GDPR for the performance of the contract—specifically to provide geographic information and services—and based on the legitimate interest in ensuring a smooth, convenient, and secure user experience pursuant to Art. 6(1)(f) GDPR. Where your consent is required for specific actions, data processing is based on Art. 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future.

    Detailed information regarding the map service follows below:

    Google Maps

    Google Maps is used to provide maps and geographic information on this website. Google Maps is a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you visit a page with embedded Google Maps, a connection to Google’s servers is established. During this process, personal data—such as your IP address and your interactions with the map—may be transmitted to Google.

    Google is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the USA. Further information on the EU-US DPF can be found at: https://www.dataprivacyframework.gov.

    For more information on how Google Maps processes your personal data, please refer to Google’s privacy policy: https://policies.google.com/privacy.

Privacy Preference Center