Privacy Policy


In the following we inform you about the processing of your personal data in the context of the use of our online offer.


Controller

markilux GmbH + Co. KG

Hansestraße 53
48282 Emsdetten

Phone: +49 (0) 25 72 / 15 31-0
Fax: +49 (0) 25 72 / 15 31 444
Mail: [email protected]


Contact person

If you have any questions about data protection, please use the contact details provided above.


Data protection officer

Johannes Meibers
meibers.datenschutz GmbH
Haus Sentmaring 9
48151 Münster

Phone: 0251 203197-0
Fax: 0251 203197-99
Mail: [email protected]


Storage period

We generally delete your personal data when it is no longer necessary for the purposes for which it was collected or otherwise processed.

If we have asked for your consent and you have given it, we will erase your personal data if you withdraw your consent and there is no other legal basis for the processing.

We will erase your personal data if you object to the processing and there are no overriding legitimate grounds for the processing or if you object to the processing for the purposes of direct marketing or related profiling.

If erasure is not possible because processing is still necessary for compliance with a legal obligation (statutory retention periods, etc.) to which we are subject or for the establishment, exercise or defense of legal claims, we will restrict the processing of your personal data.

Further information on the storage period can also be found in the following passages.


Your rights

You have the following rights with regard to your personal data:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to object to processing
- Right to data portability

You have the right to object, on grounds relating to your particular situation, at any time to processing of your personal data which is based on point (e) or (f) of Article 6(1) GDPR. 1 lit. e or f GDPR; this also applies to profiling based on these provisions. We will then no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.
If we process your personal data for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing, which includes profiling to the extent that it is related to such direct marketing. We will then no longer process your personal data for these purposes.

You have the right to withdraw your consent to the processing of your personal data at any time if you have given us such consent. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

You have the right to lodge a complaint with a supervisory authority about our processing of your personal data.


Provision of your personal data

The provision of your personal data is not required by law or contract and is not necessary for the conclusion of a contract. You are generally not obliged to provide your personal data. Should this nevertheless be the case, we will point this out to you separately when collecting your personal data (for example, by marking the mandatory fields on input forms).

Failure to provide your personal data regularly means that we will not process your personal data for one of the purposes described below and you will not be able to take advantage of an offer related to the respective processing (example: you will not receive our newsletter without providing your email address).


Web hosting

We use external services for web hosting. These services may have access to personal data that is processed as part of the use of our online offering. Further information on the services used, the scope of data processing and the technologies and procedures used when using the respective services can be found in the further information on the services we use at the end of this passage and under the links provided there.

Google Cloud
Provider: In the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America.
Website: https://cloud.google.com/
Further information & data protection: https://policies.google.com/?hl=de
The transfer of personal data to third countries depends on the respective Google service and is subject to the various EU standard contractual clauses, insofar as these are offered by Google. Further information on this and Google's responsibility can be found at the following link https://business.safety.google/gdpr/. You can view a copy of the EU standard contractual clauses there. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an appropriate level of data protection on the basis of a decision by the European Commission.


Webserver log files

We process your personal data in order to be able to display our online offering to you and to ensure the stability and security of our online offering. Information (e.g. requested element, URL called up, operating system, date and time of the request, browser type and version used, IP address, protocol used, amount of data transferred, user agent, referrer URL, time zone difference to Greenwich Mean Time (GMT) and/or HTTP status code) is stored in so-called log files (access log, error log, etc.).

If we have asked you for your consent and you have given it, the legal basis for the processing is Art. 6 para. 1 lit. a GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest here is the proper display of our online offering and ensuring the stability and security of our online offering.


Security

For security reasons and to protect the transmission of your personal data and other confidential content, we use encryption on our domain. You can recognize this in the browser line by the character string "https://" and the lock symbol.


Content Delivery Networks

We use content delivery networks from external services to optimize the loading time, stability and security of our online offer.

If we have asked you for your consent and you have given it, the legal basis for the processing is Art. 6 para. 1 lit. a GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest here is the optimization of the loading time, stability and security of our online offering.

Profiling (for the purposes of advertising, personalized information, etc.) may also occur in the context of the use of external services. Profiling can also take place across services and devices. Further information on the services used, the scope of data processing and the technologies and procedures used when using the respective services, as well as whether profiling takes place when using the respective services and, if applicable, information on the logic involved and the scope and intended effects of such processing for you can be found in the further information on the services we use at the end of this passage and under the links provided there.

Cloudflare CDN
Provider: Cloudflare, Inc, United States of America.
Website: www.cloudflare.com/de-de/
Further Information & Privacy: www.cloudflare.com/de-de/privacypolicy/
Guarantee: EU Standard Contractual Clauses. You can request a copy of the EU standard contractual clauses from us. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an appropriate level of data protection on the basis of a decision by the European Commission.


Contacting us

If you contact us, we will process your personal data in order to process your contact.

If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6 para. 1 lit. a GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the processing of your contact. If the processing is necessary to fulfill a contract with you or to carry out pre-contractual measures based on your request, the legal basis for the processing is also Art. 6 para. 1 lit. b GDPR.

We use external services to provide and maintain our email inboxes. These services may have access to personal data that is processed when you contact us. Further information on the services used, the scope of data processing and the technologies and procedures used when using the respective services can be found below in the further information on the services we use and under the links provided there:

Gmail
Provider: In the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America.
Website: www.google.com/intl/de/gmail/about/
Further information & data protection: https://policies.google.com/?hl=de
The transfer of personal data to third countries depends on the respective Google service and is subject to the various EU standard contractual clauses, insofar as these are offered by Google. Further information on this and Google's responsibility can be found at the following link https://business.safety.google/gdpr/. You can view a copy of the EU standard contractual clauses there. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an appropriate level of data protection on the basis of a decision by the European Commission.

We use support systems (appointment booking systems, live chats, ticket systems or helpdesks etc.) and use external services to support the processing of your contact. These services may have access to personal data that is processed when you contact us via a support system. Further information on the services used, the scope of data processing and the technologies and procedures for using the respective services can be found below in the further information on the services we use and under the links provided there:

HubSpot
Provider: HubSpot, Inc., United States of America.
Website: www.hubspot.de/
Further information & data protection: https://legal.hubspot.com/de/legal-stuff and https://legal.hubspot.com/de/privacy-policy
Guarantee: EU standard contractual clauses. You can request a copy of the EU standard contractual clauses from us. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an appropriate level of data protection on the basis of a decision by the European Commission.

SAP Cloud for Customer
Provider: SAP Deutschland SE & Co. KG, Germany.
Website: www.sap.com/germany/index.html
Further information & data protection: www.sap.com/germany/about/trust-center/data-privacy.html


Cookies & similar technologies

Cookies are used. Cookies are text information that is stored on your end device. A distinction is made between session cookies, which are deleted immediately after you close your browser, and persistent cookies, which are only deleted after a certain period of time.

In addition to cookies, similar technologies (tracking pixels, web beacons, etc.) may also be used. The following information on cookies also applies to similar technologies. These statements also apply to further processing in connection with cookies and similar technologies (analysis & marketing etc.). This also applies in particular to any consent you may have given for the use of cookies. This also extends to other technologies and to further processing in connection with cookies and similar technologies.

Cookies can be used to enable the use of certain functions. Cookies can also be used to measure the reach of our online offer, to design it in line with requirements and interests and thus to optimize our online offer and our marketing. Cookies can be used by us and by external services.

We use a consent tool to manage the cookies used and the related consents. Details on the cookies used (purpose, storage period, external service if applicable, etc.) and the consent tool can be found in the following passages and in the consent tool we use.

If we have asked you for your consent and you have given it, the legal basis for the processing is Art. 6 para. 1 lit. a GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the management of the cookies used and the related consents. Depending on the purpose of the processing, our legitimate interests can be found in the following passages.

You can prevent the storage of cookies by setting your browser accordingly. Below we provide you with links for typical browsers where you can find further information on managing cookie settings:
- Firefox: https://support.mozilla.org/de/kb/verbesserter-schutz-aktivitatenverfolgung-desktop
- Chrome: https://support.google.com/chrome/answer/95647?hl=en&hlrm=en
- Internet Explorer / Edge: https://support.microsoft.com/de-de/windows/l%C3%B6schen-und-verwalten-von-cookies-168dab11-0753-043d-7c16-ede5947fc64d
- Safari: https://support.apple.com/de-de/guide/safari/sfri11471/mac
- Opera: https://help.opera.com/de/latest/web-preferences/#cookies
- Yandex: https://browser.yandex.com/help/personal-data-protection/cookies.html

Further objection options can be found under the following links: www.youronlinechoices.eu/, https://youradchoices.ca/en/tools, https://optout.aboutads.info/?c=2&lang=EN and https://optout.networkadvertising.org/?c=1.

If you prevent the storage of cookies, this may affect the proper functioning of our online offer. If you delete all cookies, the above settings will also be lost and must be made again.

In addition, you can activate the "Do-Not-Track" function of your browser to signal that you do not wish to be tracked. Below we provide you with links for typical browsers where you can find further information on the "Do-Not-Track" setting:
- Firefox: https://support.mozilla.org/de/kb/wie-verhindere-ich-dass-websites-mich-verfolgen
- Chrome: https://support.google.com/chrome/answer/2790761?co=GENIE.Platform%3DDesktop&hl=en
- Internet Explorer / Edge: https://support.microsoft.com/de-de/windows/verwenden-von-do-not-track-in-internet-explorer-11-ad61fa73-d533-ce96-3f64-2aa3a332e792
- Opera: https://help.opera.com/de/latest/security-and-privacy/
- Safari no longer supports the "Do-Not-Track" function since February 2019. The following link can be used to prevent cross-site tracking in Safari https://support.apple.com/de-de/guide/safari/sfri40732/12.0/mac
- Yandex: https://yandex.com/support/browser/personal-data-protection/ytp.html

You can also revoke or manage your consent with regard to the cookies used in the consent tool we use.


Newsletter

If we have asked you for your consent and you have given it, we will process your e-mail address in order to carry out e-mail marketing and, if necessary, other personal data in order to address you personally. The legal basis for the processing is Art. 6 para. 1 lit. a GDPR. The content of the email marketing is specifically described when your consent is obtained. The email marketing also contains information about us, our goods and services.

We use the so-called double opt-in procedure to prevent possible misuse of your personal data. For this purpose, after collecting your e-mail address, we will send you an e-mail to the e-mail address you have provided, in which we ask you to confirm that you actually wish to receive e-mail marketing. The legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest here is the legally compliant implementation of email marketing.

We log the time at which you give your consent and the time of your confirmation as well as your IP address and the content of your declaration of consent in order to be able to prove that your consent has been obtained in accordance with the law. The legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the legally compliant implementation of email marketing.

We use external services for email marketing. Further information on the services used, the scope of data processing and the technologies and procedures used when using the respective services, as well as whether profiling takes place when using the respective services and, if applicable, information on the logic involved and the scope and intended effects of such processing for you can be found in the further information on the services we use at the end of this passage and under the links provided there.

You can revoke your consent at any time. The withdrawal of your consent does not affect the lawfulness of processing based on consent before its withdrawal. To withdraw your consent, you can use the link provided for this purpose in the emails or contact us using the contact details provided above.

If you have withdrawn your consent, we reserve the right to process your personal data in a so-called blacklist/blocklist in order to ensure that no further email marketing is carried out in connection with this personal data in the future. The legal basis for processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the avoidance of unwanted email marketing.

We process your personal data in the context of tracking or performance measurement in order to measure the reach of our email marketing, to design it in line with requirements and interests and thus to optimize our email marketing. This may also involve profiling (for the purposes of advertising, personalized information, etc.). Profiling can also take place across services and devices. If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6 para. 1 lit. a GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the optimization of our email marketing. A separate withdrawal of your consent or objection in relation to tracking or performance measurement is unfortunately not possible. You must use the above options to withdraw your consent or object to the processing of your personal data for the purpose of email marketing as a whole.

CleverReach
Provider: CleverReach GmbH & Co. KG, Germany.
Website: www.cleverreach.com/de/
Further information & data protection: www.cleverreach.com/de/datenschutz/

HubSpot
Provider: HubSpot, Inc, United States of America
Website: www.hubspot.de/
Further information & data protection: https://legal.hubspot.com/de/legal-stuff and https://legal.hubspot.com/de/privacy-policy
Guarantee: EU standard contractual clauses. You can request a copy of the EU standard contractual clauses from us. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an appropriate level of data protection on the basis of a decision by the European Commission.


Analysis & Marketing

We process your personal data in order to measure the reach of our online offer, to design it in line with your needs and interests and thus to optimize our online offer and our marketing.

If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6 para. 1 lit. a GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the optimization of our online offer and our marketing.

We use external services for analysis and marketing. This may also involve profiling (for the purposes of advertising, personalized information, etc.). Profiling can also take place across services and devices. Further information on the services used, the scope of data processing and the technologies and procedures used when using the respective services, as well as whether profiling takes place when using the respective services, and, if applicable Information on the logic involved and the scope and intended effects of such processing for you can be found in the further information on the services we use at the end of this passage and under the links provided there.

Further information on cookies & similar technologies can be found above.

Google Ads Conversion Tracking
Provider: In the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America.
Website: https://support.google.com/google-ads/answer/1722022?hl=de
Further information & data protection: https://policies.google.com/?hl=de
The transfer of personal data to third countries depends on the respective Google service and is subject to the various EU standard contractual clauses, insofar as these are offered by Google. Further information on this and Google's responsibility can be found at the following link https://business.safety.google/gdpr/. You can view a copy of the EU standard contractual clauses there. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which ensures compliance with an adequate level of data protection on the basis of a decision by the European Commission.

Google Ads Advanced Conversions
Provider: In the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America.
Website: https://support.google.com/google-ads/answer/9888656?hl=de
Further information & data protection: https://policies.google.com/?hl=de
The transfer of personal data to third countries depends on the respective Google service and is subject to the various EU standard contractual clauses, insofar as these are offered by Google. Further information on this and Google's responsibility can be found at the following link https://business.safety.google/gdpr/. You can view a copy of the EU standard contractual clauses there. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which ensures compliance with an adequate level of data protection on the basis of a decision by the European Commission.

Google Analytics 4
Provider: In the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America.
Website: https://support.google.com/analytics/answer/10089681?hl=de
Further information & data protection: https://support.google.com/analytics/answer/6004245?hl=de and https://policies.google.com/?hl=de
The transfer of personal data to third countries depends on the respective Google service and is subject to the various EU standard contractual clauses, insofar as these are offered by Google. Further information on this and Google's responsibility can be found at the following link https://business.safety.google/gdpr/. You can view a copy of the EU standard contractual clauses there. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which ensures compliance with an adequate level of data protection on the basis of a decision by the European Commission.

Google Remarketing
Provider: In the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America.
Website: https://support.google.com/google-ads/answer/2453998
Further information & data protection: https://policies.google.com/?hl=de
The transfer of personal data to third countries depends on the respective Google service and is subject to the various EU standard contractual clauses, insofar as these are offered by Google. Further information on this and Google's responsibility can be found at the following link https://business.safety.google/gdpr/. You can view a copy of the EU standard contractual clauses there. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which ensures compliance with an adequate level of data protection on the basis of a decision by the European Commission.

Google Tag Manager
Provider: In the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America.
Website: https://support.google.com/tagmanager/answer/6102821?hl=de
Further information & data protection: https://policies.google.com/?hl=de
The transfer of personal data to third countries depends on the respective Google service and is subject to the various EU standard contractual clauses, insofar as these are offered by Google. Further information on this and Google's responsibility can be found at the following link https://business.safety.google/gdpr/. You can view a copy of the EU standard contractual clauses there. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which ensures compliance with an adequate level of data protection on the basis of a decision by the European Commission.

HubSpot
Provider: HubSpot, Inc, United States of America.
Website: www.hubspot.de/
Further information & data protection: https://legal.hubspot.com/de/legal-stuff and https://legal.hubspot.com/de/privacy-policy
Guarantee: EU standard contractual clauses. You can request a copy of the EU standard contractual clauses from us. The provider has joined the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an adequate level of data protection on the basis of a decision by the European Commission.

LinkedIn Conversion Tracking
Provider: If you are located in the EU, the European Economic Area (EEA) or Switzerland, this service is provided by LinkedIn Ireland Unlimited Company, Ireland. If you are located outside the EU, the European Economic Area (EEA) or Switzerland, this service is provided by LinkedIn Corporation, United States of America.
Website: https://business.linkedin.com/de-de/marketing-solutions/conversion-tracking
Further information & data protection: https://de.linkedin.com/legal/privacy-policy?trk=homepage-basic_footer-privacy-policy and https://de.linkedin.com/legal/cookie-policy?trk=homepage-basic_footer-cookie-policy
Guarantee: EU standard contractual clauses. You can request a copy of the EU standard contractual clauses from us.

LinkedIn Insight tag
Provider: If you are located in the EU, the European Economic Area (EEA) or Switzerland, this service is provided by LinkedIn Ireland Unlimited Company, Ireland. If you are located outside the EU, the European Economic Area (EEA) or Switzerland, this service is provided by LinkedIn Corporation, United States of America.
Website: https://business.linkedin.com/de-de/marketing-solutions/insight-tag
Further information & data protection: https://de.linkedin.com/legal/privacy-policy?trk=homepage-basic_footer-privacy-policy and https://de.linkedin.com/legal/cookie-policy?trk=homepage-basic_footer-cookie-policy
Guarantee: EU standard contractual clauses. You can request a copy of the EU standard contractual clauses from us.

Meta Pixel with Custom Audiences
Provider: Meta Platforms Ireland Limited, Ireland. Meta Platforms Ireland Limited is a subsidiary of Meta Platforms, Inc., United States of America.
Website: www.facebook.com/business/help/744354708981227?id=2469097953376494
Weitere Informationen & Datenschutz: www.facebook.com/business/help/742478679120153?id=1205376682832142&recommended_by=218844828315224, www.facebook.com/business/help/1474662202748341?id=2469097953376494&locale=de_DE, www.facebook.com/privacy/policy/, https://de-de.facebook.com/policies/cookies/, www.facebook.com/help/566994660333381?ref=dp and https://de-de.facebook.com/help/568137493302217
Guarantee: EU Standard Contractual Clauses. You can request a copy of the EU standard contractual clauses from us. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which ensures compliance with an adequate level of data protection on the basis of a decision by the European Commission.

Meta Pixel with Custom Audiences and advanced data matching
Provider: Meta Platforms Ireland Limited, Ireland. Meta Platforms Ireland Limited is a subsidiary of Meta Platforms, Inc., United States of America.
Website: www.facebook.com/business/help/744354708981227?id=2469097953376494
Weitere Informationen & Datenschutz: www.facebook.com/business/help/742478679120153?id=1205376682832142&recommended_by=218844828315224, www.facebook.com/business/help/1474662202748341?id=2469097953376494&locale=en_DE, https://de-de.facebook.com/business/help/611774685654668, www.facebook.com/privacy/policy/, https://de-de.facebook.com/policies/cookies/, www.facebook.com/help/566994660333381?ref=dp and https://de-de.facebook.com/help/568137493302217
Guarantee: EU Standard Contractual Clauses. You can request a copy of the EU standard contractual clauses from us. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an appropriate level of data protection on the basis of a decision by the European Commission.


Social media presences

We maintain social media presences with external services in order to communicate with users there and thus optimize our online offer and our marketing.

This privacy policy also applies to the following social media presences:
- Facebook: www.facebook.com/MarkiluxUSA
- Pinterest: www.pinterest.de/markiluxus/
- Youtube: www.youtube.com/user/markiluxINT
- Instagram: www.instagram.com/markiluxusa/

If we have asked you for your consent and you have given it, the legal basis for the processing is Art. 6 para. 1 lit. a GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest here is the optimization of our online offering and our marketing.

Profiling (for the purposes of advertising, personalized information, etc.) may also occur in the context of the use of external services. Profiling can also take place across services and devices. Further information on the services used, the scope of data processing and the technologies and procedures used when using the respective services, as well as whether profiling takes place when using the respective services and, if applicable, information on the logic involved and the scope and intended effects of such processing for you can be found in the further information on the services we use at the end of this passage and under the links provided there.

Facebook
Provider: Meta Platforms Ireland Limited, Ireland. Meta Platforms Ireland Limited is a subsidiary of Meta Platforms, Inc, United States of America.
Website: www.facebook.com
The provider and we are joint controllers. We have concluded a corresponding agreement with the provider. You can view this agreement at www.facebook.com/legal/terms/page_controller_addendum and www.facebook.com/legal/controller_addendum.
Further information & data protection: https://developers.facebook.com/docs/plugins/, www.facebook.com/legal/terms/information_about_page_insights_data, www.facebook.com/privacy/policy/, https://de-de.facebook.com/policies/cookies/, www.facebook.com/help/566994660333381?ref=dp and https://de-de.facebook.com/help/568137493302217
Guarantee: EU Standard Contractual Clauses. You can request a copy of the EU standard contractual clauses from us. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an adequate level of data protection on the basis of a decision by the European Commission.

Instagram
Provider: Meta Platforms Ireland Limited, Ireland. Meta Platforms Ireland Limited is a subsidiary of Meta Platforms, Inc, United States of America.
Website: www.instagram.com
Further information & data protection: https://help.instagram.com/581066165581870 and https://help.instagram.com/519522125107875
Guarantee: EU standard contractual clauses. You can request a copy of the EU standard contractual clauses from us. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an adequate level of data protection on the basis of a decision by the European Commission.

Pinterest
Provider: For users who are not based in the United States of America, the service is provided by Pinterest Europe Ltd, Ireland. For users located in the United States of America, the service is provided by Pinterest Inc, United States of America.
Website: www.pinterest.de/
Further information & data protection: https://policy.pinterest.com/de
Guarantee: EU standard contractual clauses. You can request a copy of the EU standard contractual clauses from us.

YouTube
Provider: In the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America.
Website: www.youtube.com
Further information & data protection: https://policies.google.com/?hl=de
The transfer of personal data to third countries depends on the respective Google service and is subject to the various EU standard contractual clauses, insofar as these are offered by Google. Further information on this and Google's responsibility can be found at the following link https://business.safety.google/gdpr/. You can view a copy of the EU standard contractual clauses there. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an appropriate level of data protection on the basis of a decision by the European Commission.


Social media content/plugins

We use social media content/plugins from external services to show you content and functions of the external services and thus optimize our online offer and our marketing.

If we have asked you for your consent and you have given it, the legal basis for the processing is Art. 6 para. 1 lit. a GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest here is the optimization of our online offering and our marketing.

Profiling (for the purposes of advertising, personalized information, etc.) may also occur in the context of the use of external services. Profiling can also take place across services and devices. Further information on the services used, the scope of data processing and the technologies and procedures used when using the respective services, as well as whether profiling takes place when using the respective services and, if applicable, information on the logic involved and the scope and intended effects of such processing for you can be found in the further information on the services we use at the end of this passage and under the links provided there.

YouTube
Provider: In the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America.
Website: www.youtube.com
Further information & data protection: https://policies.google.com/?hl=de
The transfer of personal data to third countries depends on the respective Google service and is subject to the various EU standard contractual clauses, insofar as these are offered by Google. Further information on this and Google's responsibility can be found at the following link https://business.safety.google/gdpr/. You can view a copy of the EU standard contractual clauses there. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an appropriate level of data protection on the basis of a decision by the European Commission.


Fonts & scripts

We use fonts and scripts from external services in order to be able to display our online offer to you and to always guarantee up-to-date fonts and scripts.

If we have asked you for your consent and you have given it, the legal basis for the processing is Art. 6 para. 1 lit. a GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest here is the proper display of our online offering and the guarantee of up-to-date fonts and scripts.

Profiling (for the purposes of advertising, personalized information, etc.) may also occur in the context of the use of external services. Profiling can also take place across services and devices. Further information on the services used, the scope of data processing and the technologies and procedures used when using the respective services, as well as whether profiling takes place when using the respective services and, if applicable, information on the logic involved and the scope and intended effects of such processing for you can be found in the further information on the services we use at the end of this passage and under the links provided there.

Google Fonts
Provider: In the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America.
Website: https://fonts.google.com/
Further information & data protection: https://policies.google.com/?hl=de
The transfer of personal data to third countries depends on the respective Google service and is subject to the various EU standard contractual clauses, insofar as these are offered by Google. Further information on this and Google's responsibility can be found at the following link https://business.safety.google/gdpr/. You can view a copy of the EU standard contractual clauses there. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an appropriate level of data protection on the basis of a decision by the European Commission.


Maps

We use maps from external services to show you our location and to enable you to use the other functions of these external services in connection with the maps.

If we have asked you for your consent and you have given it, the legal basis for the processing is Art. 6 para. 1 lit. a GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest here is the simplified use of maps.

Profiling (for the purposes of advertising, personalized information, etc.) may also occur in the context of the use of external services. Profiling can also take place across services and devices. Further information on the services used, the scope of data processing and the technologies and procedures used when using the respective services, as well as whether profiling takes place when using the respective services and, if applicable, information on the logic involved and the scope and intended effects of such processing for you can be found in the further information on the services we use at the end of this passage and under the links provided there.

Google Maps
Provider: In the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America.
Website: www.google.de/maps
Further information & data protection: https://policies.google.com/?hl=de
The transfer of personal data to third countries depends on the respective Google service and is subject to the various EU standard contractual clauses, insofar as these are offered by Google. Further information on this and Google's responsibility can be found at the following link https://business.safety.google/gdpr/. You can view a copy of the EU standard contractual clauses there. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an adequate level of data protection on the basis of a decision by the European Commission.

Matterport
Provider: Matterport, Inc, United States of America.
Website: https://matterport.com/de
Further Information & Privacy: https://matterport.com/de/node/44
Guarantee: EU Standard Contractual Clauses. You can request a copy of the EU standard contractual clauses from us.


Review platforms

We use review platforms and process your personal data in order to have our services evaluated and thus optimize our online offer and our marketing. For this purpose, we also integrate so-called widgets of the rating platforms, for example to show that we use a rating platform and how our services are rated.

If we have asked you for your consent and you have given it, the legal basis for the processing is Art. 6 para. 1 lit. a GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the optimization of our online offer and our marketing.

If we or the rating platforms we use have asked for your consent and you have given it, we or the rating platforms we use process your personal data in order to remind you to submit a rating. The legal basis for the processing is Article 6(1)(a) GDPR.

For more information on the review platforms we use, the scope of data processing and the technologies and procedures for using the respective review platforms, please refer to the further information on the review platforms we use at the end of this passage and the links provided there.

Trusted Shops
Provider: Trusted Shops AG, Germany.
Website: www.trustedshops.de/bewertungen/
Further information & data protection: www.trustedshops.de/impressum/#datenschutz


Applications

If you apply to us, we will process your personal data in order to carry out the application process and make a decision on the establishment of an employment relationship. At the end of the application process, we restrict the processing of your personal data and delete or destroy it no later than 6 months after you have received the rejection or return the application documents to you and delete or destroy any copies, unless you have consented to us continuing to use your personal data.

If we have asked you for your consent and you have given it, the legal basis for the processing is Art. 6 para. 1 lit. a GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is the proper execution of the application procedure and, if necessary, the defense against claims due to the rejection of an application. If the processing is necessary for the decision on the establishment of an employment relationship, the legal basis for the processing is also Section 26 (1) sentence 1 BDSG.


Captchas

We use captchas to protect our online offering from abusive, automated and/or automated entries (for example in forms) and to prevent any misuse.

If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6 para. 1 lit. a GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest here is the protection of our online offering and the prevention of misuse.

We use external services to provide the captchas. This may also involve profiling. Profiling can also take place across services and devices. Further information on the services used, the scope of data processing and the technologies and procedures used when using the respective services, as well as whether profiling takes place when using the respective services and, if applicable, information on the logic involved and the scope and intended effects of such processing for you can be found in the further information on the services we use at the end of this passage and under the links provided there.

Google reCAPTCHA
Provider: In the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America.
Website: www.google.com/recaptcha/
Further information & data protection: https://policies.google.com/?hl=de
The transfer of personal data to third countries depends on the respective Google service and is subject to the various EU standard contractual clauses, insofar as these are offered by Google. Further information on this and Google's responsibility can be found at the following link https://business.safety.google/gdpr/. You can view a copy of the EU standard contractual clauses there. The provider has signed up to the EU-US Data Privacy Framework (www.dataprivacyframework.gov), which guarantees compliance with an appropriate level of data protection on the basis of a decision by the European Commission.


Dynamic Yield

We use the services of Dynamic Yield Ltd. With the personalization tool Dynamic Yield, our website is optimized to make your website visit a personal experience through tailor-made recommendations and content. In doing so, we use the page content you access to recommend relevant content to you. Dynamic Yield collects pseudonymized information about your usage activities on our website for this purpose. Cookies are used for this purpose, through which only pseudonymized information is stored under a randomly generated ID (pseudonym). A direct personal reference is therefore not possible. You can object to this collection at any time by clicking on this link and activating the opt-out. An opt-out cookie will be set that prevents the future collection of data from your visit to this website.