1.General Information

With this privacy policy, we inform you about which personal data (“data”) we process, for what purposes this is done, and what rights you are entitled to. This policy applies to our website, mobile applications, and our social media presences.

2. Data We Process

We process in particular the following types of data:
Master data (e.g. name, address)
Contact data (e.g. email address, telephone number)
Contract and payment data
Usage data (e.g. visited pages, access times)
Communication and metadata (e.g. IP address)
Event data (e.g. Facebook)

3. Purposes of Data Processing

Data processing is carried out, among other things, for:
Contract processing and customer service
Communication and handling of inquiries
Security and abuse prevention
Marketing and reach measurement
Tracking, conversion measurement, and audience building
Optimization of our online offering

4. Legal Bases

Processing is carried out on the following legal bases: Consent (Art. 6 para. 1 lit. a GDPR) Performance of a contract / pre-contractual measures (Art. 6 para. 1 lit. b GDPR) Legal obligation (Art. 6 para. 1 lit. c GDPR) Legitimate interest (Art. 6 para. 1 lit. f GDPR) In addition, national data protection regulations apply (e.g. the German Federal Data Protection Act – BDSG). This privacy policy also applies to requirements under the Swiss Data Protection Act (DSG)

5. Security Measures

We implement technical and organizational security measures to protect personal data against loss, access, or misuse. Our website uses TLS/SSL encryption (HTTPS)

6. Data Transfer to Third Countries

If data is processed outside the EU/EEA, this is done only in compliance with legal requirements (e.g. adequacy decisions, standard contractual clauses, or consent). For certain US companies, the EU–US Data Privacy Framework may apply.

7. Deletion and Retention

We delete personal data as soon as it is no longer required for the respective purpose, provided no statutory retention obligations apply (e.g. tax or commercial law retention periods).

8. Rights of Data Subjects

You have the following rights in particular:
Right of access (Art. 15 GDPR)
Right to rectification (Art. 16 GDPR)
Right to erasure (Art. 17 GDPR)
Right to restriction of processing (Art. 18 GDPR)
Right to data portability (Art. 20 GDPR)
Right to object to processing (Art. 21 GDPR)
Withdrawal of granted consent
Right to lodge a complaint with a data protection authority

9. Cookies and Consent

We use cookies for technical functionality, security, and analysis. Non-essential cookies are set only with consent. You can change or withdraw your cookie settings at any time (e.g. via the link in the website footer).

10. Business Services / Online Shop

For orders and contract processing, we process necessary customer data (e.g. delivery address, payment data). External service providers (e.g. shipping companies, payment providers) may be used for delivery and payment. Data is shared only to the extent necessary.
Used Service Providers and Services
To organize and carry out our business activities, we use external providers (e.g. tools, plugins, platforms). These support us in particular in shop operations, communication, marketing, and internal processes.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest).

Payment Service Providers
For secure and efficient payments, we use external payment service providers (e.g. PayPal, Klarna, Apple Pay, Google Pay, Visa, Mastercard). Payment data is processed directly by the respective providers. We usually receive only a payment confirmation or rejection, but no full card or account details. Depending on the provider, an identity or credit check may be carried out. The data protection provisions of the respective payment service providers apply. Legal basis: Art. 6 para. 1 lit. b GDPR (performance of contract).
Depending on the provider, an identity or credit check may be performed. The data protection regulations of the respective payment service providers also apply.
Legal basis: Art. 6 para. 1 lit. b GDPR (performance of a contract).

Web Hosting and Server Log Files
To provide our website, we process technical access data (e.g. IP address, browser type, time of access). This data is used in particular for security, stability, and error analysis.
Log files are generally stored for a maximum of 30 days and then deleted or anonymized.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest).

Contact
If you contact us (e.g. by email, contact form, or social media), we process your information to handle the inquiry and for communication.
Legal bases: Art. 6 para. 1 lit. b GDPR (inquiry/contract), Art. 6 para. 1 lit. f GDPR (organization & communication).

Chat Functions / Chatbots
If you use our chat functions, we process the content of your messages as well as technical usage data. Depending on the platform, metadata (e.g. time, device data) may also be collected.
You can withdraw consent or object to processing at any time.
Legal bases: consent (Art. 6 para. 1 lit. a), contract (Art. 6 para. 1 lit. b), legitimate interest (Art. 6 para. 1 lit. f GDPR).

Newsletter & Marketing Communication
We only send newsletters with your consent (double opt-in). You can unsubscribe at any time via the unsubscribe link.
We can store deregistration data for up to 3 years for verification purposes.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (proof/organization).
Web analysis & tracking
We use analytics and tracking tools (e.g., Google Analytics, Meta Pixel) to measure reach, user behavior, and advertising effectiveness. Pseudonymous user profiles may be created in the process. IP addresses are shortened (IP masking) wherever possible.
Legal basis: Consent (Art. 6 para. 1 lit. a GDPR) or legitimate interest (Art. 6 para. 1 lit. f GDPR).

Ratings & Reviews
We may use external services (e.g., Judge.me) to display and manage customer reviews. This may involve processing technical data (e.g., IP address) and order information for verification purposes.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest).

Social media presences
We maintain profiles on social networks (e.g., Instagram, Facebook) to communicate with users and provide content. Data may also be processed outside the EU. These providers often create user profiles for advertising and market research purposes.
For details and opt-out options, please refer to the privacy policies of the respective platforms.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)