Data Protection Notice according to Art. 13 GDPR
Name and Address of the Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is:
GPO GmbH
Wildmoos 9
82266 Inning
Germany
Phone: +49 8143 99 20 87 0
Email: info@gp-optics.com
General Information on Data Processing
Legal Basis for the Processing of Personal Data
In accordance with Art. 13 GDPR, we inform you of the legal bases for our data processing. Unless the legal basis is specified in the data protection notice, the following applies:
The legal basis for obtaining consent is Art. 6(1)(a) in conjunction with Art. 7 GDPR. The legal basis for processing for the fulfillment of our services and implementation of contractual measures, as well as for responding to inquiries, is Art. 6(1)(b) GDPR. The legal basis for processing to fulfill our legal obligations is Art. 6(1)(c) GDPR. If the processing of your data is necessary to protect a legitimate interest of our company or a third party and if the interests, fundamental rights, and freedoms of the data subject do not override the first-mentioned interest, Art. 6(1)(f) GDPR serves as the legal basis for the processing. In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6(1)(d) GDPR serves as the legal basis.
Data Deletion and Storage Period
We adhere to the principles of data minimization pursuant to Art. 5(1)(c) GDPR and storage limitation pursuant to Art. 5(1)(e) GDPR. We store your personal data only for as long as is necessary to achieve the purposes stated here or as stipulated by the retention periods provided for by law. After the respective purpose ceases to apply or after these retention periods have expired, the corresponding data will be deleted as quickly as possible.
Note on Data Transfer to Third Countries
Our website also integrates tools from companies based in third countries. If these tools are active, your personal data may be transferred to the servers of the respective companies. The level of data protection in third countries generally does not correspond to EU data protection law. This creates a risk that your data may be passed on to authorities in these countries. We have no influence on these processing activities.
External Links
This website may contain links to third-party websites or to other websites under our responsibility. If you follow a link to a website outside of our responsibility, please note that these websites have their own data protection information. We assume no responsibility or liability for these external websites and their privacy notices. Therefore, before using these websites, please check whether you agree with their privacy policies.
You can recognize external links either by the fact that they are displayed in a slightly different color from the rest of the text or are underlined. Your cursor will indicate external links when you move it over such a link. Only when you click on an external link will your personal data be transferred to the link's destination. In this process, the operator of the other website receives, in particular, your IP address, the time at which you clicked the link, the page on which you clicked the link, and other information that you can find in the privacy notice of the respective provider.
Please also note that individual links may lead to data transfer outside the European Economic Area. This could allow foreign authorities to access your data. You may not have any legal remedies against this data access. If you do not want your personal data to be transferred to the link's destination or to be exposed to unwanted access by foreign authorities, please do not click on any links.
Rights of the Data Subject
As a data subject within the meaning of the GDPR, you have the option of asserting various rights. The rights of data subjects arising from the GDPR are the right of access (Article 15), the right to rectification (Article 16), the right to erasure (Article 17), the right to restriction of processing (Article 18), the right to object (Article 21), the right to lodge a complaint with a supervisory authority, and the right to data portability (Article 20).
Right to withdraw consent:
Some data processing operations are only possible with your express consent. You have the option to withdraw your consent at any time. However, this does not affect the lawfulness of the data processing that took place up to the point of withdrawal.
Right to object:
If the processing is based on Art. 6(1)(e) or (f) GDPR, you as the data subject may object to the processing of your personal data at any time for reasons arising from your particular situation. This right also applies to profiling based on these provisions within the meaning of Art. 4(4) GDPR. Unless we can demonstrate a legitimate interest for the processing which overrides your interests, rights, and freedoms, or if the processing serves the establishment, exercise, or defense of legal claims, we will cease processing your data after an objection has been made.
If personal data is processed for direct marketing purposes, you also have the right to object at any time. The same applies to profiling that is connected with direct marketing. Here too, we will no longer process personal data as soon as you object.
Right to lodge a complaint with a supervisory authority:
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, without prejudice to any other administrative or judicial remedy.
Right to data portability:
If your data is processed automatically on the basis of consent or the fulfillment of a contract, you have the right to receive this data in a structured, commonly used, and machine-readable format. You also have the right to request the transfer and provision of the data to another controller, insofar as this is technically feasible.
Right of access, rectification, and erasure:
You have the right to receive information about your processed personal data regarding the purpose of the data processing, the categories, the recipients, and the duration of storage. If you have any questions on this topic or on other topics concerning personal data, you can of course contact us using the contact options provided in the legal notice.
Right to restriction of processing:
You can assert the right to restriction of processing of your personal data at any time. To do so, you must meet one of the following requirements:
- You contest the accuracy of the personal data. For the duration of the verification of the accuracy, you have the right to request a restriction of the processing.
- If processing is unlawful, you can request the restriction of the use of the data as an alternative to erasure.
- If we no longer need your personal data for the purposes of processing, but you need the data for the establishment, exercise, or defense of legal claims, you can request the restriction of processing as an alternative to erasure.
- If you object to the processing pursuant to Art. 21(1) GDPR, a balancing of your interests and ours will be carried out. Until this balancing has taken place, you have the right to request the restriction of processing.
A restriction of processing means that the personal data, apart from storage, may only be processed with your consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
Provision of the Website (Web Host)
Our website is hosted by:
IONOS SE
Elgendorfer Strasse 57, 56410 Montabaur
Germany
When you visit our website, we automatically collect and store information in so-called server log files. Your browser automatically transmits this information to our server or to the server of our hosting company.
This includes:
- IP address of the website visitor's end device
- Device used
- Hostname of the accessing computer
- Visitor's operating system
- Browser type and version
- Name of the retrieved file
- Time of the server request
- Amount of data
- Information on whether the data retrieval was successful
This data is not merged with other data sources.
Instead of operating this website on our own server, we can also have it operated on the server of an external service provider (hosting company), which we have named above in this case. The personal data collected by this website is then stored on the servers of the hosting company. In addition to the data mentioned above, the web host also stores for us, for example, contact requests, contact details, names, website access data, meta and communication data, contract data, and other data generated via a website.
The legal basis for the processing of this data is Art. 6(1)(f) GDPR. Our legitimate interest is the technically error-free presentation and optimization of this website. If the website is accessed to enter into contract negotiations with us or to conclude a contract, this serves as a further legal basis (Art. 6(1)(b) GDPR). In the event that we have commissioned a hosting company, a data processing agreement exists with this service provider.
Use of Local Storage Items, Session Storage Items, and Cookies
Our website uses Local Storage Items, Session Storage Items, and/or Cookies. Local storage is a mechanism that allows data to be stored within the browser on your end device. This data usually includes user preferences, such as the "day" or "night mode" of a website, and is retained until you manually delete the data. Session storage is very similar to local storage, whereas the storage period only lasts for the current session, i.e., until the current tab is closed. After that, the session storage items are deleted from your end device. Cookies are pieces of information that a web server (a server that provides web content) stores on your end device in order to be able to identify that end device. They are either temporarily deleted for the duration of a session (session cookies) and after the end of your visit to a website or stored permanently (permanent cookies) on your end device until you delete them yourself or they are automatically deleted by your web browser.
These objects can also be stored on your end device by third-party companies when you visit our site (third-party requests). This enables us as the operator and you as a visitor to this website to use certain services from third parties that are installed on this website. Examples of this include the processing of payment services or the display of videos.
These mechanisms have a wide range of applications. They can improve the functionality of a website, control shopping cart functions, increase the security and convenience of using the website, and carry out analyses of visitor flows and behavior. Depending on the individual functions, these must be classified in terms of data protection law. If they are necessary for the operation of the website and are intended to provide certain functions (shopping cart function) or serve to optimize the website (e.g., cookies to measure visitor behavior), then their use is based on Art. 6(1)(f) GDPR. As a website operator, we have a legitimate interest in storing local storage items, session storage items, and cookies for the technically error-free and optimized provision of our services. In all other cases, local storage items, session storage items, and cookies are only stored with your express consent (Art. 6(1)(a) GDPR).
Insofar as local storage items, session storage, or cookies are used by third-party companies or for analysis purposes, we will inform you about this separately in this data protection notice. Your required consent will be requested and can be revoked at any time.
Use of External Services
External services are used on our website. External services are services from third-party providers that are used on our website. This can be for various reasons, for example, for embedding videos or for the security of the website. When these services are used, personal data is also passed on to the respective providers of these external services. If we do not have a legitimate interest in using these services, we will obtain your consent, which can be revoked at any time, as a visitor to our website before use (Art. 6(1)(a) GDPR).
Affiliate Network
As part of one or more affiliate partner programs, advertisements and links to the websites of our advertising partners are integrated on this website, by means of which we can earn money through advertising cost reimbursement, for example, if you make a purchase from this advertising partner. Our advertising partners use cookies or comparable recognition technologies (e.g., device fingerprinting) to be able to trace the origin of the orders. This allows our advertising partners to recognize that you have clicked on the corresponding link on our website.
Processing only takes place if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Art. 6(1)(a) GDPR). Without your consent, data processing will not take place in the manner described above. If you withdraw your consent (e.g., via the consent banner or other options provided on this website), we will stop this data processing. The lawfulness of the processing carried out until the withdrawal remains unaffected.
Adcell
We use the Adcell service on our website. The provider of the service is Firstlead GmbH, Rosenfelder St. 15-16, 10315 Berlin, Germany.
Further information can be found in the provider's data protection information at the following URL: https://www.adcell.de/news/meldungen/dsgvo/datenschutz-grundverordnung-bei-adcell.
Analytics
We process personal data of website visitors to analyze user behavior. By evaluating the data obtained, we are able to compile information about the use of the individual components of our website. This enables us to increase the user-friendliness of our website. The analysis tools used could, for example, be used to create user profiles for the display of targeted or interest-based advertising messages, recognize our website visitors on their next visit to our website, measure their click/scroll behavior, their downloads, create heat maps, recognize page views, measure the duration of the visit or the bounce rates, and trace the origin of the website visitors (city, country, from which page the visitor comes). With the help of the analysis tools, our market research and marketing activities can be improved.
Processing only takes place if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Art. 6(1)(a) GDPR). Without your consent, data processing will not take place in the manner described above. If you withdraw your consent (e.g., via the consent banner or other options provided on this website), we will stop this data processing. The lawfulness of the processing carried out until the withdrawal remains unaffected.
Plausible Analytics
We use the Plausible Analytics service on our website. The provider of the service is Plausible Insights OÜ, Västriku tn 2, 50403, Tartu, Estonia.
Further information can be found in the provider's data protection information at the following URL: https://plausible.io/data-policy.
SiteBehaviour
We use the SiteBehaviour service on our website. The provider of the service is SiteBehaviour, Inc., 3066 Bonaventure Dr, Mississauga, ON L4T 2J2, Canada.
Further information can be found in the provider's data protection information at the following URL: https://docs.sitebehaviour.com/privacy/privacy-policy.
SourceBuster JS
We use the SourceBuster JS service on our website. The provider of the service is Sourcebuster, United Arab Emirates.
As this service is hosted locally on the web server, no data is transferred to third parties.
Consent Management
To comply with data protection requirements, we use a consent management tool on our website. We use this tool to obtain the necessary consent for setting cookies or using external services. The consents are stored.
The processing is necessary for compliance with a legal obligation to which the controller (operator of the website) is subject. The legal basis for the processing is therefore Art. 6(1)(c) GDPR.
Complianz GDPR/CCPA Cookie Consent
We use the Complianz GDPR/CCPA Cookie Consent service on our website. The provider of the service is Complianz B.V., Kalmarweg 14-5, 9723 JG Groningen, Netherlands.
As this service is hosted locally on the web server, no data is transferred to third parties.
Content Delivery Network (CDN)
We use a Content Delivery Network (CDN) to optimize the performance and availability of our website. For this purpose, your IP address and information about when you visited our website are processed by this service provider, who provides this network. You can find all further information on data processing by this service provider in their privacy notice.
We base this processing on a legitimate interest (Art. 6(1)(f) GDPR).
Our legitimate interest in using a Content Delivery Network is to be able to display our website as quickly, securely, and reliably as possible.
Bootstrap CDN
We use the Bootstrap CDN service on our website. The provider of the service is Volentio JSD Limited, Suite 2a1, Northside House, Mount Pleasant, Barnet, EN4 9EB, United Kingdom.
The use of the service may result in data transfer to a third country (USA). The provider is certified under the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.
Further information can be found in the provider's data protection information at the following URL: https://www.jsdelivr.com/terms/privacy-policy.
CloudFlare
We use the CloudFlare service on our website. The provider of the service is Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany.
The use of the service may result in data transfer to a third country (USA). The provider is certified under the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.
Further information can be found in the provider's data protection information at the following URL: https://www.cloudflare.com/privacypolicy/.
Digital Ocean
We use the Digital Ocean service on our website. The provider of the service is DigitalOcean, LLC, 101 Avenue Of The Americas 10 New York, NY 10013, USA.
The use of the service may result in data transfer to a third country (USA). The provider is certified under the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.
Further information can be found in the provider's data protection information at the following URL: https://www.digitalocean.com/legal/privacy-policy.
Google APIs CDN
We use the Google APIs CDN service on our website. The provider of the service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The use of the service may result in data transfer to a third country (USA). The provider is certified under the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.
Further information can be found in the provider's data protection information at the following URL: https://business.safety.google/privacy.
Display Optimization
We use tools to optimize the presentation of our website. Among other things, these tools help to display the website in other languages or make it more accessible.
Processing only takes place if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Art. 6(1)(a) GDPR). Without your consent, data processing will not take place in the manner described above. If you withdraw your consent (e.g., via the consent banner or other options provided on this website), we will stop this data processing. The lawfulness of the processing carried out until the withdrawal remains unaffected.
WPML
We use the WPML service on our website. The provider of the service is OnTheGoSystems Ltd., 22/F 3 Lockhart Road, Wanchai, Hong Kong, China.
As this service is hosted locally on the web server, no data is transferred to third parties.
We base this processing on a legitimate interest (Art. 6(1)(f) GDPR).
This application is required to ensure the full functionality of the website. It is a language tool that is considered essential.
Forms and Surveys
We use tools on our website that allow us to create surveys and forms and integrate them into our website. These tools are used to conduct surveys on various topics on our website. The forms allow us to create and integrate inquiries and information on any topic into the website. These forms and surveys can be filled out or answered by you as a website visitor. In the course of visiting the website and filling out or answering the surveys or forms, personal data from you as a website visitor is processed. This includes in particular your IP address, as well as other data entered by you as a website visitor in the forms or in the context of surveys. This personal data is processed by the website operator and by the provider of the survey or form tool (our processor) and stored on their servers.
Processing only takes place if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Art. 6(1)(a) GDPR). Without your consent, data processing will not take place in the manner described above. If you withdraw your consent (e.g., via the consent banner or other options provided on this website), we will stop this data processing. The lawfulness of the processing carried out until the withdrawal remains unaffected.
ALFRIGHT Services
We use the ALFRIGHT Services on our website. The provider of the service is Lukmann Consulting GmbH, Packerstrasse 131a, A-8561 Söding, Austria.
We base this processing on a legitimate interest (Art. 6(1)(f) GDPR).
This service helps us to keep our privacy notice up-to-date and legally compliant. We therefore base this on the legal grounds of legitimate interest.
Map Service
We use a map service on this website. In order for the map to be used and displayed on the website, the map must be loaded from the provider's server. This involves the transfer of your IP address to the provider's server. Depending on the provider, cookies and other technologies, including fonts, are loaded. You can find more details on this in the provider's privacy policy.
Processing only takes place if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Art. 6(1)(a) GDPR). Without your consent, data processing will not take place in the manner described above. If you withdraw your consent (e.g., via the consent banner or other options provided on this website), we will stop this data processing. The lawfulness of the processing carried out until the withdrawal remains unaffected.
Google Maps
We use the Google Maps service on our website. The provider of the service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The use of the service may result in data transfer to a third country (USA).
Further information can be found in the provider's data protection information at the following URL: https://policies.google.com/privacy?hl=de
Mapbox
We use the Mapbox service on our website. The provider of the service is Mapbox, Inc., 1714 14th Street NW Washington, DC 20009-4309, USA.
The use of the service may result in data transfer to a third country (USA). The provider is certified under the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.
Further information can be found in the provider's data protection information at the following URL: https://www.mapbox.com/legal/privacy/.
StoreLocatorWidgets
We use the StoreLocatorWidgets service on our website. The provider of the service is StoreLocatorWidgets.com, USA.
The use of the service may result in data transfer to a third country (USA).
Further information can be found in the provider's data protection information at the following URL: https://www.storelocatorwidgets.com/privacy.
Payment Service Provider
We integrate payment services from a company specializing in these services on our website. When you make a purchase from us, your payment data (e.g., name, payment amount, bank account details, credit card number) is transmitted to our payment service provider and processed by them for the purpose of payment processing. The contractual and data protection provisions of the provider we have selected apply to these transactions.
Processing only takes place if you consent to this data processing (via our consent banner on the website). The legal basis for this processing is consent (Art. 6(1)(a) GDPR). Without your consent, data processing will not take place in the manner described above. If you withdraw your consent (e.g., via the consent banner or other options provided on this website), we will stop this data processing. The lawfulness of the processing carried out until the withdrawal remains unaffected.
Stripe
We use the Stripe service on our website. The provider of the service is Stripe Payments Europe Limited, The One Building, 1, Lower Grand Canal Street, Dublin 2, Ireland.
The use of the service may result in data transfer to a third country (USA). The provider is certified under the EU-U.S. Data Privacy Framework and therefore offers an adequate level of data protection.
Further information can be found in the provider's data protection information at the following URL: https://stripe.com/at/privacy.
Contact by Phone or Email
In accordance with legal requirements, we have provided a telephone number and email address on our website. The data transmitted in these ways is automatically stored by us in order to process corresponding inquiries or to be able to contact the person making the inquiry. This data will not be passed on to third parties without consent.
If contact is made by telephone or via our email address for pre-contractual or contractual purposes, the processing of personal data is based on the legal grounds of Art. 6(1)(b) GDPR. For all other contacts made by you, the processing of personal data by us is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Presence on Facebook
Social networks process the personal data of their users to a large extent. When you visit our profiles, your IP address and other information about your devices are processed, which allows the IP addresses to be assigned to individual users. We have no influence on this data processing. We would like to point out that you use our profiles on social networks and their functions on your own responsibility. You can find details on data processing in the operator's privacy policy.
We have a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
For details, please refer to Facebook's privacy policy: https://www.facebook.com/about/privacy/.
The purpose of our profiles on social media platforms is to increase our internet presence and the associated greater visibility. Therefore, the legal basis to be used is legitimate interest pursuant to Art. 6(1)(f) GDPR. Furthermore, with regard to the processing activities by the social networks, reference should be made to their own legal bases (e.g., consent pursuant to Art. 6(1)(a) GDPR), which you can find in the respective privacy policy.
In principle, we are jointly responsible with the social media platform for the data processing operations triggered when you visit our profile. Therefore, you can assert your rights as a data subject pursuant to Art. 15 et seq. GDPR against the social media platform as well as against us. However, we would like to point out that we have no influence on the data processing by the social media platform.
Presence on Instagram
Social networks process the personal data of their users to a large extent. When you visit our profiles, your IP address and other information about your devices are processed, which allows the IP addresses to be assigned to individual users. We have no influence on this data processing. We would like to point out that you use our profiles on social networks and their functions on your own responsibility. You can find details on data processing in the operator's privacy policy.
We have a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
You can find detailed information on the handling of personal data in the following Instagram privacy policy: https://help.instagram.com/519522125107875.
The purpose of our profiles on social media platforms is to increase our internet presence and the associated greater visibility. Therefore, the legal basis to be used is legitimate interest pursuant to Art. 6(1)(f) GDPR. Furthermore, with regard to the processing activities by the social networks, reference should be made to their own legal bases (e.g., consent pursuant to Art. 6(1)(a) GDPR), which you can find in the respective privacy policy.
In principle, we are jointly responsible with the social media platform for the data processing operations triggered when you visit our profile. Therefore, you can assert your rights as a data subject against the social media platform as well as against us. However, we would like to point out that we have no influence on the data processing by the social media platform.
Presence on LinkedIn
Social networks process the personal data of their users to a large extent. When you visit our profiles, your IP address and other information about your devices are processed, which allows the IP addresses to be assigned to individual users. We have no influence on this data processing. We would like to point out that you use our profiles on social networks and their functions on your own responsibility. You can find details on data processing in the operator's privacy policy.
We have a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.
You can find detailed information on the handling of personal data in the following LinkedIn privacy policy: https://www.linkedin.com/legal/privacy-policy.
The purpose of our profiles on social media platforms is to increase our internet presence and the associated greater visibility. Therefore, the legal basis to be used is legitimate interest pursuant to Art. 6(1)(f) GDPR. Furthermore, with regard to the processing activities by the social networks, reference should be made to their own legal bases (e.g., consent pursuant to Art. 6(1)(a) GDPR), which you can find in the respective privacy policy.
In principle, we are jointly responsible with the social media platform for the data processing operations triggered when you visit our profile. Therefore, you can assert your rights as a data subject pursuant to Art. 15 et seq. GDPR against the social media platform as well as against us. However, we would like to point out that we have no influence on the data processing by the social media platform.
Presence on YouTube
Social networks process the personal data of their users to a large extent. When you visit our profiles, your IP address and other information about your devices are processed, which allows the IP addresses to be assigned to individual users. We have no influence on this data processing. We would like to point out that you use our profiles on social networks and their functions on your own responsibility. You can find details on data processing in the operator's privacy policy.
We have a profile on YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
You can find detailed information on the handling of personal data in the following YouTube privacy policy: https://policies.google.com/privacy?hl=en.
The purpose of our profiles on social media platforms is to increase our internet presence and the associated greater visibility. Therefore, the legal basis to be used is legitimate interest pursuant to Art. 6(1)(f) GDPR. Furthermore, with regard to the processing activities by the social networks, reference should be made to their own legal bases (e.g., consent pursuant to Art. 6(1)(a) GDPR), which you can find in the respective privacy policy.
In principle, we are jointly responsible with the social media platform for the data processing operations triggered when you visit our profile. Therefore, you can assert your rights as a data subject pursuant to Art. 15 et seq. GDPR against the social media platform as well as against us. However, we would like to point out that we have no influence on the data processing by the social media platform.
Google also transfers and processes data in the USA. There is currently no adequate level of protection for data transfers to the USA. For this reason, there are risks associated with the processing of the data. WhatsApp uses standard contractual clauses and is part of the Data Privacy Framework, whereby Google undertakes to ensure an adequate level of data protection.
Web Shop
When you visit our web shop, we collect data that is necessary for the use of the web shop and the processing of your order.
Purpose and type of data processing:
- Order processing: We collect personal data when you place an order.
- Customer account: If you create a customer account, we also store your access data.
- Legal basis: The processing is necessary for the performance of a contract in accordance with Art. 6(1)(b) GDPR.
Disclosure of personal data:
- Shipping service provider: To deliver your order, we pass on your address data to the shipping service provider commissioned with the delivery of the goods. This is done exclusively for the purpose of fulfilling the contract. Legal basis: Art. 6(1)(b) GDPR
- Payment service provider: For the processing of payments, we pass on payment data to the commissioned payment service providers. The data is processed in accordance with Art. 6(1)(b) GDPR for the performance of the contract.
Personal data is only stored for as long as is necessary for the purposes for which it was collected or as required by statutory retention periods. As soon as the purpose of the processing ceases to apply or after the statutory retention periods have expired, the data is routinely deleted or blocked in accordance with the statutory provisions.
