Privacy policy

Data protection information in accordance with Art. 13 GDPR

Name and address of the controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is

NASH Vertical Brands GmbH
Schwarzottstraße 2a
2620 Neunkirchen
Austria

info@nash.eu

General information on data processing

Legal basis for the processing of personal data

In accordance with Art. 13 GDPR, we inform you of the legal basis of our data processing. If the legal basis is not specified in the data protection notice, the following applies:
The legal basis for obtaining consent is Art. 6 para. 1 lit. a i.V.m. Art. 7 GDPR. The legal basis for the processing for the fulfillment of our services and the implementation of contractual measures as well as for answering inquiries is Art. 6 para. 1 lit. b GDPR. The legal basis for processing for the fulfillment of our legal obligations is Art. 6 para. 1 lit. c GDPR. If the processing of your data is necessary to safeguard a legitimate interest of our company or a third party and if the interests, fundamental rights and freedoms of the data subject do not outweigh the former interest, Art. 6 para. 1 lit. f GDPR serves as the legal basis for the processing. In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 para. 1 lit. d GDPR serves as the legal basis.

Data erasure and storage duration

We adhere to the principles of data minimization pursuant to Art. 5 para. 1 lit. c GDPR and storage limitation pursuant to Art. 5 para. 1 lit. e GDPR. We only store your personal data for as long as is necessary to achieve the purposes stated here or as provided for by the retention periods stipulated by law. After the respective purpose no longer applies or after these retention periods have expired, the corresponding data will be deleted as quickly as possible.

Note on the transfer of data to third countries

Tools from companies based in third countries are also integrated on our website. If these tools are active, your personal data may be transmitted to the servers of the respective companies. The level of data protection in third countries generally does not correspond to EU data protection law. There is therefore a risk that your data may be passed on to authorities in these countries. We have no influence on these processing activities.

External links

This website may contain links to third-party websites or to other websites under our responsibility. If you follow a link to a website outside our responsibility, please note that these websites have their own data protection information. We accept no responsibility or liability for these third-party websites and their data protection notices. Therefore, before using these websites, please check whether you agree with their data protection declarations.

You can recognize external links either by the fact that they are displayed in a different colour from the rest of the text or underlined. Your cursor will show you external links when you move it over such a link. Only when you click on an external link will your personal data be transferred to the destination of the link. In particular, the operator of the other website will receive your IP address, the time at which you clicked on the link, the page on which you clicked on the link and other information that you can find in the data protection information of the respective provider.

Please also note that individual links may lead to data being transferred outside the European Economic Area. This could give foreign authorities access to your data. You may not have any legal remedies against this data access. If you do not want your personal data to be transferred to the link destination or even to be exposed to unwanted access by foreign authorities, please do not click on any links.

Rights of the data subject

As a data subject within the meaning of the GDPR, you have the opportunity to assert various rights. The data subject rights arising from the GDPR are the right of access (Article 15), the right to rectification (Article 16), the right to erasure (Article 17), the right to restriction of processing (Article 18), the right to object (Article 21), the right to lodge a complaint with a supervisory authority and the right to data portability (Article 20).

Right of withdrawal:

Some data processing can only take place with your express consent. You have the option to withdraw your consent at any time. However, this does not affect the lawfulness of data processing up to the point of withdrawal.

Right to object:

If the processing is based on Art. 6 para. 1 lit. e or f GDPR, you as the data subject can object to the processing of personal data concerning you at any time for reasons arising from your particular situation. You also have this right in the case of profiling based on these provisions within the meaning of Art. 4(4) GDPR. If we cannot demonstrate a legitimate interest in the processing that outweighs your interests, rights and freedoms or if the processing serves to assert, exercise or defend legal claims, we will refrain from processing your data after the objection has been made.

If the processing of personal data serves the purpose of direct advertising, you also have the right to object at any time. The same applies to profiling in connection with direct advertising. Here too, we will no longer process personal data as soon as you object.

Right to lodge a complaint with a supervisory authority:

If you consider that the processing of personal data relating to you infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, without prejudice to any other administrative or judicial remedy.

Right to data portability:

If your data is processed automatically on the basis of consent or fulfillment of a contract, you have the right to receive this data in a structured, commonly used and machine-readable format. You also have the right to request the transfer and provision of the data to another controller, insofar as this is technically feasible.

Right of access, rectification and erasure:

You have the right to obtain information about your processed personal data with regard to the purpose of the data processing, the categories, the recipients and the duration of storage. If you have any questions on this topic or other topics relating to personal data, you can of course contact us using the contact details provided in the legal notice.

Right to restriction of processing:

You can request the restriction of the processing of your personal data at any time. To do so, you must fulfill one of the following conditions:

  • You contest the accuracy of the personal data. You have the right to request the restriction of processing for the duration of the verification of accuracy.

  • If the processing is unlawful, you can request the restriction of the use of the data as an alternative to erasure.

  • If we no longer need your personal data for the purposes of processing, but you need the data for the assertion, exercise or defense of legal claims, you can request the restriction of processing as an alternative to erasure.

  • If you object to the processing pursuant to Art. 21 (1) GDPR, your interests and ours will be weighed up. Until this balancing has taken place, you have the right to request the restriction of processing.

Restriction of processing means that, with the exception of storage, personal data may only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.

Provision of the website (web host)

Our website is hosted by:

Shopify International Ltd.
2nd Floor 1 and 2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32
Ireland

When you visit our website, we automatically collect and store information in so-called server log files. Your browser automatically transmits this information to our server or to the server of our hosting company.

These are

  • IP address of the website visitor's end device

  • Device used

  • Host name of the accessing computer

  • Operating system of the visitor

  • Browser type and version

  • Name of the retrieved file

  • Time of the server request

  • Amount of data

  • Information on whether the retrieval of the data was successful

This data is not merged with other data sources.

Instead of operating this website on our own server, we can also have it operated on the server of an external service provider (hosting company), which we have named above in this case. The personal data collected by this website is then stored on the hosting company's servers. In addition to the data mentioned above, the web host also stores contact requests, contact data, names, website access data, meta and communication data, contract data and other data generated via a website for us, for example.

The legal basis for the processing of this data is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the technically error-free presentation and optimization of this website. If the website is accessed in order to enter into contractual negotiations with us or to conclude a contract, a further legal basis is provided by Art. 6 para. 1 lit. b GDPR. In the event that we have commissioned a hosting company, there is an order processing contract with this service provider.

Use of local storage items, session storage items and cookies

Our website uses local storage items, session storage items and/or cookies. Local storage is a mechanism that enables the storage of data within the browser on your end device. This data usually contains user preferences, such as the "day" or "night" mode of a website, and is retained until you delete the data manually. Session storage is very similar to local storage, whereas the storage period only lasts during the current session, i.e. until the current tab is closed. The session storage items are then deleted from your end device. Cookies are information that a web server (server that provides web content) stores on your end device in order to be able to identify this end device. They are either stored temporarily for the duration of a session (session cookies) and deleted at the end of your visit to a website or permanently (permanent cookies) on your end device until you delete them yourself or they are automatically deleted by your web browser.

These objects may also be stored on your device by third-party companies when you visit our website (third-party requests). This enables us as the operator and you as a visitor to this website to make use of certain third-party services that are installed on this website. Examples of this include the processing of payment services or the display of videos.

These mechanisms can be used in a variety of ways. They can improve the functionality of a website, control shopping cart functions, increase the security and convenience of website use and carry out analyses of visitor flows and behavior. Depending on the individual functions, these must be classified in terms of data protection law. If they are necessary for the operation of the website and intended to provide certain functions (shopping cart function) or serve to optimize the website (e.g. cookies to measure visitor behavior), they are used on the basis of Art. 6 para. 1 lit. f GDPR. As the website operator, we have a legitimate interest in the storage of local storage items, session storage items and cookies for the technically error-free and optimized provision of our services. In all other cases, local storage items, session storage items and cookies are only stored with your express consent (Art. 6 para. 1 lit. a GDPR).

If local storage items, session storage or cookies are used by third-party companies or for analysis purposes, we will inform you about this separately in this data protection notice. Your required consent will be requested and can be revoked at any time.

Use of external services

External services are used on our website. External services are services from third-party providers that are used on our website. This can be done for various reasons, for example for embedding videos or for the security of the website. When using these services, personal data is also passed on to the respective providers of these external services. If we do not have a legitimate interest in using these services, we will obtain your consent as a visitor to our website, which can be revoked at any time, before using them (Art. 6 para. 1 lit. a GDPR).

Affiliate network

As part of one or more affiliate partner programs, advertisements and links to the websites of our advertising partners are integrated on this website, by means of which we can earn money through the reimbursement of advertising costs, for example if you make a purchase from this advertising partner. Our advertising partners use cookies or comparable recognition technologies (e.g. device fingerprinting) in order to be able to trace the origin of orders. This allows our advertising partners to recognize that you have clicked on the corresponding link on our website.

Processing only takes place if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Art. 6 para. 1 lit. a GDPR). Without your consent, data will not be processed in the manner described above. If you withdraw your consent (e.g. via the consent banner or other options provided on this website), we will terminate this data processing. This does not affect the lawfulness of the processing that took place before you withdrew your consent.

AWIN

We use the AWIN service on our website. The provider of the service is AWIN AG, Eichhornstraße 3, 10785 Berlin, Germany.

Further information can be found in the provider's data protection information at the following URL: https://www.awin.com/at/datenschutzerklarung.

Analytics

We process personal data of website visitors to analyze user behavior. By analyzing the data obtained, we are able to compile information about the use of the individual components of our website. This enables us to increase the user-friendliness of our website. The analysis tools used can be used, for example, to create user profiles for the display of targeted or interest-based advertising messages, recognize our website visitors the next time they visit our website, measure their click/scroll behaviour and downloads, create heat maps, recognize page views, measure the duration of visits or bounce rates, and trace the origin of website visitors (city, country, which page the visitor comes from). The analysis tools help us to improve our market research and marketing activities.

Processing only takes place if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Art. 6 para. 1 lit. a GDPR). Without your consent, data will not be processed in the manner described above. If you withdraw your consent (e.g. via the consent banner or other options provided on this website), we will terminate this data processing. The

legality of the processing carried out until the revocation remains unaffected.

Bugsnag

We use the Bugsnag service on our website. The provider of the service is SmartBear Software Inc, 110 Sutter Street, San Francisco, CA 94104, USA.

By using the service, data may be transferred to a third country (USA). The provider is certified in accordance with the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.

Further information can be found in the provider's data protection information at the following URL: https://smartbear.com/privacy/.

Google Analytics

We use the Google Analytics service on our website. The provider of the service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The use of the service may result in data being transferred to a third country (USA). The provider is certified in accordance with the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.

Further information can be found in the provider's data protection information at the following URL: https://business.safety.google/privacy.

LinkedIn Insight Tag

We use the LinkedIn Insight Tag service on our website. The provider of the service is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.

The use of the service may result in data being transferred to a third country (USA). The provider is certified in accordance with the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.

Further information can be found in the provider's data protection information at the following URL: https://www.linkedin.com/legal/privacy-policy.

Microsoft Clarity

We use the Microsoft Clarity service on our website. The provider of the service is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.

The use of the service may result in data being transferred to a third country (USA). The provider is certified in accordance with the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.

Further information can be found in the provider's data protection information at the following URL: https://privacy.microsoft.com/de-de/privacystatement.

Meta pixel & Facebook Conversion API

This website uses the Facebook/Meta visitor action pixel to measure conversions. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the data collected is also transferred to the USA and other third countries.

Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its transfer to Facebook. The processing carried out by Facebook after forwarding is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in an agreement on joint processing. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the data protection information when using the Facebook tool and for the secure implementation of the tool on our website in accordance with data protection law. Facebook is responsible for the data security of Facebook products. You can assert data subject rights (e.g. requests for information) regarding the data processed by Facebook directly with Facebook. If you assert your data subject rights with us, we are obliged to forward them to Facebook.

The data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

You can find further information on protecting your privacy in Facebook's privacy policy: https://de-de.facebook.com/about/privacy/.

The use of the service may result in data being transferred to a third country (USA). The provider is certified in accordance with the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.

Stape.io

We use the stape.io service on our website as a cloud tagging server to implement server-side tracking. The provider of the service is Stape Europe OÜ, Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia.

By using the service, data may be transferred to a third country (USA). The legal basis for this data transfer is the Standard Contractual Clauses (SCCs) of the EU Commission.

Further information can be found in the provider's data protection information at the following URL: https://stape.io/eu-privacy-notice and https://stape.io/gdpr.

Shopify Analytics

We use the Shopify Analytics service on our website. The provider of the service is Shopify International Ltd, 2nd Floor 1 and 2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland.

The use of the service may result in data being transferred to a third country (Canada). The European Commission has confirmed an adequate level of data protection for the country by means of an adequacy decision.

Further information can be found in the provider's data protection information at the following URL: https://www.shopify.com/legal/privacy?shpxid=1c1444d0-C70E-43BB-AD1E-BB3774A7C8C0.

TikTok Pixel (planned)

We have integrated the TikTok pixel on this website. The provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (hereinafter referred to as TikTok).

Data transfer to third countries is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.tiktok.com/legal/page/eea/privacy-policy/de-DE and https://ads.tiktok.com/i18n/official/policy/controller-to-controller.

Rating platform

We use review platforms to display collected reviews on our website and thereby build trust with users. The collected reviews are published on our website. When the website is accessed, a connection to the respective provider is established and the website visitor's data is transmitted. Personal data that is processed in the process is, for example, the IP address.

The legal basis for this processing is our legitimate interest in displaying product ratings and customer reviews (Art. 6 para. 1 lit. f GDPR).

Judge.me

We use the Judge.me service on our website. The provider of the service is Judge.me Ltd, Buckworths, 1-3 Worship Street, London EC2A 2AB, United Kingdom.

By using the service, data may be transferred to a third country (United Kingdom). The European Commission has confirmed an adequate level of data protection for the country by means of an adequacy decision.

Further information can be found in the provider's data protection information at the following URL: https://judge.me/privacy.

Trustpilot

We use the Trustpilot service on our website. The provider of the service is Trustpilot A/S, Pilestræde 58, 5, 1112 Copenhagen, Denmark.

Further information can be found in the provider's data protection information at the following URL: https://de.legal.trustpilot.com/for-reviewers/end-user-privacy-terms.

Graphics optimization tool

We use tools that support us in optimizing image content on the website. This enables us to make our website more vivid and clearer.

The legal basis for this processing is our legitimate interest in a visually appealing and well-converting website (Art. 6 para. 1 lit. f GDPR).

ImgIX

We use the ImgIX service on our website. The provider of the service is Zebrafish Labs Inc, 423 Tehama St, San Francisco, California, 94103, USA.

By using the service, data may be transferred to a third country (USA). The provider is certified in accordance with the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.

Further information can be found in the provider's data protection information at the following URL: https://imgix.com/privacy.

Consent management

In order to comply with data protection requirements, we use a consent management tool on our website. We use this tool to obtain the necessary consent for the setting of cookies or the use of external services. The consents are stored.

The processing is necessary for compliance with a legal obligation to which the controller (website operator) is subject. Art. 6 para. 1 lit. c GDPR is therefore used as the legal basis for processing.

Customer service software

We use customer service software on our website. We use this to establish contact between our website users and us in order to support visitors to the website. In order to operate this customer service software, data is collected from website users when they visit the website. In addition, we analyze the operation of this software. In this context, we process certain personal data of website users, in particular personal and electronic identification data, which may be contact data or personal identification data.

Processing only takes place if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Art. 6 para. 1 lit. a GDPR). Without your consent, data will not be processed in the manner described above. If you withdraw your consent (e.g. via the consent banner or other options provided on this website), we will terminate this data processing. This does not affect the lawfulness of the processing carried out up to the point of withdrawal.

Richpanel

We use the Richpanel service on our website. The provider of the service is Richpanel Inc, 1885 Cabana Dr, San Jose, CA 95125, USA.

By using the service, data may be transferred to a third country (USA).

Further information can be found in the provider's data protection information at the following URL: https://www.richpanel.com/privacy-policy.

Marketing

Tools are used on our website that offer services relating to campaigns, web analysis and personalization. This enables a central and comprehensive collection of all data, which in turn is necessary for the optimization and planning of digital campaigns. These services can be set and used by our advertising partners via our website to create a profile of your interests and show you relevant ads on other websites.

Processing will only take place if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Art. 6 para. 1 lit. a GDPR). Without your consent, data will not be processed in the manner described above. If you withdraw your consent (e.g. via the consent banner or other options provided on this website), we will terminate this data processing. This does not affect the lawfulness of the processing carried out up to the point of withdrawal.

Triple Whale

We use the Triple Whale service on our website. The provider of the service is Triple Whale Inc, 7th Floor, Jaffa St 224, Jerusalem, Israel.

As this service is hosted locally on the web server, no data is transferred to third parties.

Newsletter tools

As part of our marketing activities, we offer you the opportunity to subscribe to our newsletter via our website. To subscribe to the newsletter, you go through a registration process during which we check whether you are the owner of the e-mail address provided and agree to receive our newsletter. The data will remain with us or with the newsletter service commissioned by us for the duration of your voluntary registration until you unsubscribe from the newsletter. If you unsubscribe from the newsletter, you will be deleted from the distribution list. This list will not be merged with other data. However, deletion from the newsletter subscription does not mean that data stored for other purposes (e.g. customer accounts) will also be deleted.

Data will only be processed if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Art. 6 para. 1 lit. a GDPR). Without your consent, data will not be processed in the manner described above. If you withdraw your consent (e.g. via the consent banner or other options provided on this website), we will terminate this data processing. This does not affect the lawfulness of the processing carried out up to the point of withdrawal.

Klaviyo

We use the Klaviyo service on our website. The provider of the service is Klaviyo, Inc, 125 Summer St, Floor 6 Boston, MA 02111, USA.

Forms for registration and interaction with the newsletter are dynamically integrated by Klaviyo. To display these forms, your device establishes a connection to Klaviyo's servers in order to download the corresponding content. As part of this processing, your IP address is processed by Klaviyo, among other things. This processing of the dynamic integration of Klaviyo forms is based on our legitimate interest in providing our customers and website visitors with an informative and useful newsletter (Art. 6 para. 1 lit. f GDPR).

The use of the service may result in data being transferred to a third country (USA). The provider is certified in accordance with the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.

Further information can be found in the provider's data protection information at the following URL: https://www.klaviyo.com/legal/privacy-policy.

Sending newsletters to existing customers

If you order goods or services from us and enter your e-mail address, this e-mail address may subsequently be used by us to send newsletters, provided we inform you of this in advance. In such a case, only direct advertising for our own similar goods or services will be sent via the newsletter. You can unsubscribe from this newsletter at any time. There is a corresponding link in every newsletter for this purpose. In this case, the legal basis for sending the newsletter is Art. 6 para. 1 lit. f GDPR in conjunction with § 7 para. 3 UWG.

After you unsubscribe from the newsletter distribution list, we may store your email address in a blacklist to prevent future mailings to you. The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage in the blacklist is not limited in time. You can object to the storage if your interests outweigh our legitimate interest.

Interface software

Business processes are cheaper, faster and more error-free if they are automated with the help of software via interfaces. In this way, they can be efficiently integrated into company processes via your own website or social networks. We use interface software on our website to link different applications with each other and to transfer personal data securely from one application to another.

We base this processing on a legitimate interest (Art. 6 para. 1 lit. f GDPR). Our legitimate interest is to be able to develop and display our website as efficiently, securely and reliably as possible.

Google Tag Manager

We use the Google Tag Manager service on our website. The provider of the service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The use of the service may result in data being transferred to a third country (USA). The provider is certified in accordance with the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.

Further information can be found in the provider's data protection information at the following URL: https://business.safety.google/privacy.

Web fonts

This site uses so-called web fonts for the uniform display of fonts, which are provided by an external provider and are loaded by the browser when the website is accessed. The provider of the web font becomes aware that our website has been accessed from your IP address, as your browser establishes a direct connection to the provider of the web font.

The legal basis for this processing is our legitimate interest in a visually appealing website (Art. 6 para. 1 lit. f GDPR).

Adobe Typekit

We use the Adobe Typekit service on our website. The provider of the service is Adobe Systems Software Ireland Limited, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland.

The use of the service may result in data being transferred to a third country (USA). The provider is certified in accordance with the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.

Further information can be found in the provider's data protection information at the following URL: https://www.adobe.com/de/privacy/policy.html.

Webshop

We offer you our products and/or services via our webshop. As part of the sale of products and/or services, we collect, process and use your personal data (e.g. your name, your contact details, but also access times, device information or your IP address) to handle the purchase and payment process.

We base this processing on a legitimate interest (Art. 6 para. 1 lit. f GDPR).

Our legitimate interest lies in the error-free presentation and optimization of our web store.

Shopify

We use the Shopify service on our website. The provider of the service is Shopify International Ltd, 2nd Floor 1 and 2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland.

The use of the service may result in data being transferred to a third country (Canada). The European Commission has confirmed an adequate level of data protection for the country by means of an adequacy decision.

Further information can be found in the provider's data protection information at the following URL: https://www.shopify.com/legal/privacy?shpxid=1c1444d0-C70E-43BB-AD1E-BB3774A7C8C0.

Advertising

Tools are used on our website that facilitate or enable the placement of advertisements and the evaluation of the success of ads placed. Personal data is processed for this purpose, in particular the IP address, access times and device information.

Processing only takes place if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Art. 6 para. 1 lit. a GDPR). Without your consent, data will not be processed in the manner described above. If you withdraw your consent (e.g. via the consent banner or other options provided on this website), we will terminate this data processing. This does not affect the lawfulness of the processing carried out up to the point of withdrawal.

Microsoft Advertising

We use the Microsoft Advertising service on our website. The provider of the service is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. By using the service, data may be transferred to a third country (USA). The provider is certified in accordance with the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.

Further information can be found in the provider's data protection information at the following URL: https://www.microsoft.com/de-de/privacy/privacystatement.

Google Ads

We use the Google Ads service on our website. The provider of the service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The use of the service may result in data being transferred to a third country (USA). The provider is certified in accordance with the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.

Further information can be found in the provider's data protection information at the following URL: https://business.safety.google/privacy.

Google Double Click

We use the Google Double Click service on our website. The provider of the service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The use of the service may result in data being transferred to a third country (USA). The provider is certified in accordance with the EU-U.S. Data Privacy Framework and therefore offers an appropriate level of data protection.

Further information can be found in the provider's data protection information at the following URL: https://business.safety.google/privacy.

LinkedIn Ads

We use the LinkedIn Ads service on our website. The provider of the service is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.

The use of the service may result in data being transferred to a third country (USA). The provider is certified in accordance with the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.

Further information can be found in the provider's data protection information at the following URL: https://www.linkedin.com/legal/privacy-policy.


Registration on the website

Visitors have the option of registering on our website. This requires the provision of personal data. Registration makes it possible to offer services or content that require special information about you. This personal data is processed and stored exclusively for the use of the corresponding service or offer. The purpose of the processing is the fulfillment of pre-contractual services, contract fulfillment or customer care.

This data is generally stored for the period during which you are registered on our website. Data may be stored for longer if this is required by law.

The processing described above in this subsection is based on the legal basis of consent (Art. 6 para. 1 lit. a GDPR). The data subject has consented to the processing of their personal data with their voluntary, explicit and prior consent. We proceed in the same way if data subjects withdraw their consent.

If registration on the website is necessary in order to process contract-related content, we rely on the legal basis for the fulfillment of a contract pursuant to Art. 6 para. 1 lit. b GDPR.

Processing of customer and contract data

We collect, process and use personal customer and contract data to establish, structure the content of and amend our contractual relationships. We collect, process and use personal data about the use of this website (usage data) only insofar as this is necessary to enable the user to use the service or to bill the user. The legal basis for this is Art. 6 para. 1 lit. b GDPR.

The customer data collected will be deleted after completion of the order or termination of the business relationship and expiry of any existing statutory retention periods. Statutory retention periods remain unaffected.

Payment service providers

We integrate payment services from a company specializing in these services on our website. When you make a purchase from us, your payment details (e.g. name, payment amount, account details, credit card number) are transmitted to our payment service provider and processed by them for the purpose of payment processing. The contractual and data protection provisions of the provider selected by us apply to these transactions.

The respective contractual and data protection provisions of the respective providers apply to this processing. The payment service providers are used on the basis of Art. 6 para. 1 lit. b GDPR (contract processing) and in the interest of the smoothest, most convenient and secure payment process possible (Art. 6 para. 1 lit. f GDPR)

Klarna

We use the Klarna service on our website. The provider of the service is Klarna Bank AB German Branch, Chausseestraße 117, 10115 Berlin, Germany.

Further information can be found in the provider's data protection information at the following URL: https://www.klarna.com/at/datenschutz/.

PayPal

We use the PayPal service on our website. The provider of the service is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449, Luxembourg.

By using the service, data may be transferred to a third country (USA).

The data transfer to the USA is based on the standard contractual clauses of the EU Commission.

Further information can be found in the provider's data protection information at the following URL: https://www.paypal.com/myaccount/privacy/privacyhub.

Contact form

On our website, you have the option of contacting us using a contact form. In particular, your contact details are required to contact us via this form.

The legal basis here is the processing for the purpose of contract fulfillment or pre-contractual measures pursuant to Art. 6 para. 1 lit. b GDPR. There may also be a legitimate interest in maintaining business relationships or responding to your inquiry for other reasons.

The legal basis for the processing of your data in this case would be Art. 6 para. 1 lit. f GDPR.

The data will be deleted when we have finally answered your request and there are no other storage obligations to the contrary.

Contact by telephone or email

We have provided a telephone number and email address on our website in accordance with legal requirements. The data transmitted via these channels is automatically stored by us in order to process corresponding inquiries or to be able to contact the person making the inquiry. We will not pass this data on to third parties without consent.

If contact is made by telephone or via our e-mail address for pre-contractual or contractual purposes, the processing of personal data is based on the legal basis of Art. 6 para. 1 lit. b GDPR. For all other contact on your part, the processing of personal data by us is based on our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.

Presence on Instagram

Social networks process personal data of their users to a large extent. When you visit our profiles, your IP address and other information about the devices you use are processed, which makes it possible to assign IP addresses to individual users. We have no influence on this data processing. We would like to point out that you use our profiles on the social networks and their functions on your own responsibility. Details on data processing can be found in the operator's privacy policy.

We have a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Detailed information on the handling of personal data can be found in the following Instagram privacy policy: https://help.instagram.com/519522125107875.

The purpose of our profiles on social media platforms is to increase our internet presence and the associated greater awareness. Therefore, the legal basis is legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Furthermore, with regard to the processing activities by the social networks, reference should be made to their own legal bases (e.g. consent pursuant to Art. 6 para. 1 lit. a GDPR), which you can find in the respective privacy policy.

In principle, we are jointly responsible with the social media platform for the data processing operations triggered when you visit our profile. You can therefore assert your rights as a data subject in accordance with Art. 15ff GDPR against the social media platform as well as against us. However, we would like to point out that we have no influence on data processing by the social media platform.

One Tree Planted, Inc

Our webshop uses the services of "OneTreePlanted", provided by One Tree Planted Inc, 145 Pine Haven Shores Rd #1000D, USA. "OneTreePlanted" is an organization dedicated to planting trees worldwide and allows our customers to purchase trees and make donations.

In order to facilitate your donation or purchase of trees, "OneTreePlanted" collects certain personal data such as your name, email address and payment information. This data is used to process donations or the purchase and to send you a confirmation.

The data processing is based on your consent. By agreeing to the use of cookies from this provider, you also consent to the processing of your data in the USA (Art 49 para 1 lit a GDPR).

Further information can be found in the provider's data protection information at the following URL : https://onetreeplanted.org/policies/privacy-policy

Ecologi

Our webshop uses the services of "Ecologi", provided by Ecologi Action Ltd, Hikenield House East Anton Court, Icknield Way, Andover, Hampshire, England, SP10 5RG. "Ecologi" is a platform that enables us to support tree planting and other sustainable projects by making donations and carrying out climate offsetting.

To enable donations or carbon offsetting, "Ecologi" collects certain personal data such as your name, email address and payment information. This data is used to process the donation or climate compensation and to send you a confirmation. The data processing is based on your consent.

Further information can be found in the provider's data protection information at the following URL : https://ecologi.com/resources/privacy-policy