Privacy Policy
Unless otherwise stated below, the provision of your personal data is neither legally nor contractually required, nor is it necessary for the conclusion of a contract. You are not obligated to provide the data. Failure to provide it will have no consequences. This only applies unless otherwise stated during the subsequent processing operations.
“Personal data” means any information relating to an identified or identifiable natural person.
Server log files
You can visit our websites without providing any personal information.
Each time you access our website, usage data is transmitted to us or our web host/IT service provider via your internet browser and stored in log files (so-called server log files). This stored data includes, for example, the name of the page accessed, the date and time of access, the IP address, the amount of data transferred, and the requesting provider.
The processing is carried out on the basis of Art. 6 (1) (f) GDPR due to our overriding legitimate interest in ensuring the smooth operation of our website and improving our offering.
Your data may be transferred to third countries outside the EU, particularly to Canada and the USA, and processed there. An adequacy decision of the EU Commission exists for Canada. An adequacy decision of the EU Commission exists for the USA: the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified under the TADPF. This data transfer is based on contractual obligations comparable to those of the EU Commission's standard contractual clauses.The processing is carried out on the basis of Art. 6 (1) (f) GDPR due to our overriding legitimate interest in ensuring the smooth operation of our website and improving our offering.
contact
Person responsible
Please contact us if you wish. The controller responsible for data processing is: Herbbio Abdin GmbH, Niermannsweg 1, 40699 Erkrath , Germany, +49 211 989 461 11, kundenservice@herbbio.de
Customer's proactive contact via email
If you initiate business contact with us via email, we will only collect your personal data (name, email address, message text) to the extent you provide it. This data processing serves to process and respond to your contact request.
If the contact serves to carry out pre-contractual measures (e.g. advice in the event of purchase interest, preparation of an offer) or concerns a contract already concluded between you and us, this data processing is carried out on the basis of Art. 6 (1) (b) GDPR.
If contact is made for other reasons, this data processing is based on Art. 6 (1) (f) GDPR, based on our overriding legitimate interest in processing and responding to your inquiry. In this case, you have the right to object to this processing of personal data concerning you based on Art. 6 (1) (f) GDPR at any time for reasons arising from your particular situation.
We will only use your email address to process your request. Your data will then be deleted in compliance with statutory retention periods unless you have consented to further processing and use.
Collection and processing when using the contact form
When you use the contact form, we collect your personal data (name, email address, message text) only to the extent you provide it. Data processing serves the purpose of establishing contact.
If the contact serves to carry out pre-contractual measures (e.g. advice in the event of purchase interest, preparation of an offer) or concerns a contract already concluded between you and us, this data processing is carried out on the basis of Art. 6 (1) (b) GDPR.
If contact is made for other reasons, this data processing is based on Art. 6 (1) (f) GDPR, based on our overriding legitimate interest in processing and responding to your inquiry. In this case, you have the right to object to this processing of personal data concerning you based on Art. 6 (1) (f) GDPR at any time for reasons arising from your particular situation.
We will only use your email address to process your request. Your data will then be deleted in compliance with statutory retention periods unless you have consented to further processing and use.
Using Google Maps API address validation
We use address validation from Google (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland, “Google”) on our website.
The purpose of data processing is to check your entries in our address forms in real time for input and spelling errors, and to supplement any missing data. If data is entered incorrectly, alternative suggestions for correcting the data will be displayed. For this purpose, the address data you enter is transmitted to the provider, where it is stored and evaluated.
Among other things, the following information may be transmitted to Google and processed there: postal addresses (country, city, postal code, street, house number), email address, telephone number.
Your data may also be transferred to the USA. For the USA, the EU Commission has issued an adequacy decision, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and is thus committed to complying with European data protection principles.
Your personal data is processed on the basis of Art. 6 (1) (f) GDPR, based on our overriding legitimate interest in maintaining a correct data basis to fulfill our contractual obligations. You have the right to object to this processing of personal data concerning you at any time for reasons arising from your particular situation.
The data is processed separately by the provider and not merged with other data. It is deleted by the provider as soon as the status of the entered data has been determined, but no later than 30 days later.
Further information on Google's terms of use and data protection can be found at: https://cloud.google.com/maps-platform/terms or at https://www.google.de/policies/privacy/ .
Customer account ordersWe use address validation from Google (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland, “Google”) on our website.
The purpose of data processing is to check your entries in our address forms in real time for input and spelling errors, and to supplement any missing data. If data is entered incorrectly, alternative suggestions for correcting the data will be displayed. For this purpose, the address data you enter is transmitted to the provider, where it is stored and evaluated.
Among other things, the following information may be transmitted to Google and processed there: postal addresses (country, city, postal code, street, house number), email address, telephone number.
Your data may also be transferred to the USA. For the USA, the EU Commission has issued an adequacy decision, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and is thus committed to complying with European data protection principles.
Your personal data is processed on the basis of Art. 6 (1) (f) GDPR, based on our overriding legitimate interest in maintaining a correct data basis to fulfill our contractual obligations. You have the right to object to this processing of personal data concerning you at any time for reasons arising from your particular situation.
The data is processed separately by the provider and not merged with other data. It is deleted by the provider as soon as the status of the entered data has been determined, but no later than 30 days later.
Further information on Google's terms of use and data protection can be found at: https://cloud.google.com/maps-platform/terms or at https://www.google.de/policies/privacy/ .
Customer account
When you open a customer account, we collect your personal data to the extent specified therein. The data processing serves the purpose of improving your shopping experience and simplifying order processing. Processing is carried out on the basis of Art. 6 (1) (a) GDPR with your consent. You can revoke your consent at any time by notifying us, without affecting the legality of the processing carried out on the basis of your consent until the revocation. Your customer account will then be deleted.
Collection, processing and transfer of personal data when placing orders
When you place an order, we collect and process your personal data only to the extent necessary to fulfill and process your order and to process your inquiries. Providing this data is required to conclude a contract. Failure to provide this data will result in no contract being concluded. Processing is based on Art. 6 (1) (b) GDPR and is necessary to fulfill a contract with you.
Your data may be shared with, for example, shipping companies, dropshipping or fulfillment providers, payment service providers, order processing service providers, and IT service providers. In all cases, we strictly adhere to legal requirements. The scope of data transfer is limited to a minimum.
Your data may be transferred to third countries outside the EU, particularly to Canada and the USA, and processed there. An adequacy decision of the EU Commission exists for Canada. An adequacy decision of the EU Commission exists for the USA: the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified under the TADPF. This data transfer is based on contractual obligations comparable to those of the EU Commission's standard contractual clauses.Reviews Advertising
Google Customer Reviews rating tool
We use the Google Customer Reviews rating tool from Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”) for our website.
After your order, we would like to ask you to rate and comment on your purchase. For this purpose, we will contact you via email using Google's survey opt-in module. The following information, among others, may be processed and transmitted to Google: order details (e.g., order ID, delivery country, expected delivery date, GTIN of the ordered products) and your email address.
Your data may be transferred to the USA. For the USA, the EU Commission has issued an adequacy decision, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself under the TADPF and is thus committed to complying with European data protection principles.
Processing is based on Art. 6 (1) (a) GDPR with your consent, provided you have expressly consented to the sharing of your data and to receiving the request for feedback. You can revoke your consent at any time with future effect, without affecting the legality of the processing carried out on the basis of your consent until the revocation.
We use the Google Customer Reviews rating tool from Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”) for our website.
After your order, we would like to ask you to rate and comment on your purchase. For this purpose, we will contact you via email using Google's survey opt-in module. The following information, among others, may be processed and transmitted to Google: order details (e.g., order ID, delivery country, expected delivery date, GTIN of the ordered products) and your email address.
Your data may be transferred to the USA. For the USA, the EU Commission has issued an adequacy decision, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself under the TADPF and is thus committed to complying with European data protection principles.
Processing is based on Art. 6 (1) (a) GDPR with your consent, provided you have expressly consented to the sharing of your data and to receiving the request for feedback. You can revoke your consent at any time with future effect, without affecting the legality of the processing carried out on the basis of your consent until the revocation.
Further information on terms of use and data protection when using Google Customer Reviews can be found at https://www.google.com/shopping/customerreviews/static/tos/de/1_01_tos.html and at https://policies.google.com/privacy?hl=de
Use of the email address for sending newslettersWe use your email address to send you information and offers via newsletter, provided you have expressly consented to this. Data processing serves exclusively for the purpose of advertising. For this purpose, we process your email address and, if applicable, other data that you have voluntarily provided when registering for our newsletter.
Processing is based on Art. 6 (1) (a) GDPR with your consent. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of your consent until the revocation.
You can unsubscribe from the newsletter at any time by using the corresponding link in the newsletter or by notifying us. Your email address will then be removed from the mailing list. Despite being removed from the mailing list, we may continue to store your email address in a so-called blacklist to prevent you from receiving newsletter emails from us in the future. This storage is based on Art. 6 (1) (f) GDPR out of our and your legitimate interest in preventing the further use of your email address to send our newsletter. You have the right to object to this processing of personal data concerning you at any time for reasons arising from your particular situation.
Use of the email address for sending direct mail
We use your email address, which we received as part of the sale of a product or service, to electronically send advertising for our own products or services that are similar to those you have already purchased from us, unless you have objected to this use. Providing the email address is necessary to conclude the contract. Failure to provide it will result in no contract being concluded. Processing is carried out on the basis of Art. 6 (1) (f) GDPR due to our overriding legitimate interest in direct advertising. You can object to this use of your email address at any time by notifying us. The contact details for exercising your objection can be found in the legal notice. You can also use the link provided for this purpose in the advertising email. There are no costs for this other than the transmission costs according to the basic rates.
Using Klaviyo
We use the service of Klaviyo Inc. (125 Summer St Floor 7, Boston, MA 02111, USA; “Klaviyo”) to send the newsletter as part of order processing.
We will forward the information you provide during newsletter registration (email address, first and last name, if applicable) to Klaviyo. Data processing serves the purpose of sending the newsletter and its statistical analysis.
To evaluate newsletter campaigns, the newsletters sent contain a 1x1 pixel graphic (tracking pixel) or a tracking link. This allows us to determine whether you have opened the newsletter and whether you have clicked on any integrated links. In this context, we collect your personal data, such as your IP address, browser type and device, and the time of access. This data can be used to create user profiles under a pseudonym. The collected data is not used to identify you personally. The collected data is used solely for statistical analysis to improve newsletter campaigns.
Your data is generally transferred to and stored on Klaviyo servers in the USA. For the USA, the EU Commission has issued an adequacy decision, the Trans-Atlantic Data Privacy Framework (TADPF). Klaviyo has certified itself according to the TADPF and is thus committed to complying with European data protection principles.
Your personal data is processed on the basis of Art. 6 (1) (f) GDPR, based on our overriding legitimate interest in a targeted, effective, and user-friendly newsletter system. You have the right to object to this processing of personal data concerning you at any time for reasons arising from your particular situation.
Further information on data protection at Klaviyo can be found at https://www.klaviyo.com/legal/privacy-notice and at https://www.klaviyo.com/legal/data-processing-agreement .
Use of email address for availability notifications
We offer a product availability notification service on our website. If an item is temporarily unavailable, you have the option of entering your email address for the respective item and being informed by email when it becomes available, provided you have consented to this. You will receive a one-time notification by email about the availability of the respective item. Processing is carried out on the basis of Art. 6 (1) (a) GDPR with your consent. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent until the revocation. You can unsubscribe from the availability notification at any time by notifying us. Your email address will then be removed from the mailing list.
Shipping service provider merchandise managementWe offer a product availability notification service on our website. If an item is temporarily unavailable, you have the option of entering your email address for the respective item and being informed by email when it becomes available, provided you have consented to this. You will receive a one-time notification by email about the availability of the respective item. Processing is carried out on the basis of Art. 6 (1) (a) GDPR with your consent. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent until the revocation. You can unsubscribe from the availability notification at any time by notifying us. Your email address will then be removed from the mailing list.
Passing on the email address to shipping companies to inform them about the shipping status
We will share your email address with the shipping company as part of the contract processing, provided you have expressly consented to this during the ordering process. This sharing serves the purpose of informing you about the shipping status by email. Processing is carried out on the basis of Art. 6 (1) (a) GDPR with your consent. You can revoke your consent at any time by notifying us or the shipping company, without affecting the legality of the processing carried out on the basis of your consent until the revocation.
Use of an external inventory management system
We use a merchandise management system to process your order. For this purpose, your personal data collected during the order process will be transferred to
JTL-Software-GmbH, Rheinstr. 7, 41836 Hückelhoven
transmitted.
The processing of your personal data serves the purpose of fulfilling the contract concluded with you and is based on Art. 6 (1) (b) GDPR.
Payment service provider credit report
Using Klarna payment options
We use the payment service of Klarna Bank AB (publ) (Sveavägen 46, 111 34 Stockholm, Sweden; "Klarna") on our website. By selecting and using payment via Klarna, the data required for payment processing will be transmitted to Klarna in order to fulfill the contract with you using the selected payment method. This processing is based on Art. 6 (1) (b) GDPR.
Cookies may be stored that enable your browser to be recognized. The resulting data processing is based on Art. 6 (1) (f) GDPR, based on our overriding legitimate interest in offering a customer-oriented range of payment methods. You have the right to object to this processing of personal data concerning you at any time for reasons arising from your particular situation.
Cookies may be stored that enable your browser to be recognized. The resulting data processing is based on Art. 6 (1) (f) GDPR, based on our overriding legitimate interest in offering a customer-oriented range of payment methods. You have the right to object to this processing of personal data concerning you at any time for reasons arising from your particular situation.
“Pay Later” (invoice), “Pay Now” (payment by direct debit, credit card, instant bank transfer), “Financing” (installment purchase)
For certain payment methods such as "Pay Later" (invoice), "Pay Now" (payment by direct debit, credit card, instant bank transfer), and "Financing" (installment purchase), Klarna reserves the right to obtain a credit report based on mathematical-statistical procedures using credit agencies.
For this purpose, Klarna transmits the personal data required for a credit check, such as first and last name, address, gender, email address, IP address and data related to the order, to a credit agency for the purpose of identity and credit checks and uses the information received on the statistical probability of a payment default to make a balanced decision about the establishment, implementation or termination of the contractual relationship. The credit report may contain probability values (score values) that are calculated on the basis of scientifically recognized mathematical-statistical procedures and whose calculation includes, among other things, address data. Your legitimate interests are taken into account in accordance with the statutory provisions. The data processing serves the purpose of the credit check for the initiation of a contract. The processing is carried out on the basis of Art. 6 (1) (f) GDPR due to our overriding legitimate interest in protection against payment default if Klarna makes advance payments. You have the right to object to the processing of your personal data based on Art. 6 (1) (f) GDPR at any time by notifying Klarna, for reasons related to your particular situation. Providing this data is necessary for concluding the contract using your preferred payment method. Failure to provide this data will result in the contract not being concluded using your chosen payment method.
Further information, in particular which credit agencies Klarna passes on your personal data to, can be found for Germany at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies and for Austria at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_at/credit_rating_agencies .
General information about Klarna can be found for Germany at: https://www.klarna.com/de/ and for Austria at https://www.klarna.com/at/ . Your personal data will be treated by Klarna in accordance with the applicable data protection regulations and in accordance with the information in Klarna's privacy policy for Germany at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/privacy and for Austria at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_at/privacy .
Cookies
Our website uses cookies. Cookies are small text files that are stored in the internet browser or by the internet browser on a user's computer system. When a user visits a website, a cookie may be stored on the user's operating system. This cookie contains a characteristic string that allows the browser to be uniquely identified when the website is visited again.
Cookies are stored on your computer. Therefore, you have full control over the use of cookies. By selecting the appropriate technical settings in your internet browser, you can be notified before cookies are set and decide whether to accept them individually, as well as prevent the storage of cookies and the transmission of the data they contain. Cookies already stored can be deleted at any time. However, please note that in this case, you may not be able to use all the functions of this website to their full extent.
The following links will tell you how to manage (including deactivate) cookies in the most important browsers:
Chrome: https://support.google.com/accounts/answer/61416?hl=de
Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/cookies-in-microsoft-edge-lB6schen-63947406-40ac-c3b8-57b9-2a946a29ae09
Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/cookies-in-microsoft-edge-lB6schen-63947406-40ac-c3b8-57b9-2a946a29ae09
Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablassen
Technically necessary cookies
Unless otherwise stated in the privacy policy below, we only use technically necessary cookies to make our website more user-friendly, effective, and secure. Furthermore, cookies enable our systems to recognize your browser even after you change pages and to offer you services. Some functions of our website cannot be offered without the use of cookies. These require that the browser is recognized even after you change pages.
The use of cookies or similar technologies is based on Section 25 (2) of the Telemedia Act (TDDDG). Your personal data is processed on the basis of Art. 6 (1) (f) GDPR, based on our overriding legitimate interest in ensuring the optimal functionality of the website and a user-friendly and effective design of our offering.
You have the right to object to the processing of personal data concerning you at any time for reasons related to your particular situation.
Use of Complianz GDPR Cookie ConsentWe use the Complianz GDPR Cookie Consent plugin from Complianz BV (Atoomweg 6B 9743 AK Groningen, Netherlands; "Complianz") on our website.
The plug-in allows you to grant consent to data processing via the website, in particular the use of cookies, as well as to exercise your right to withdraw consent you have already granted. Data processing serves the purpose of obtaining and documenting the necessary consent to data processing and thus complying with legal obligations. Cookies may be used for this purpose. Among other things, the following information may be collected and transmitted to Complianz: a uniquely identifiable ID and consent status. This data will not be shared with third parties.
Data processing is carried out to fulfill a legal obligation on the basis of Art. 6 (1) (c) GDPR.
Further information on data protection at Complianz can be found at: https://complianz.io/legal/privacy-statement/?cmplz_region_redirect=true®ion=eu
analysis
Use of Google Analytics 4
We use the web analysis service Google Analytics from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; “Google”) on our website.
The data processing serves the purpose of analyzing this website and its visitors, as well as for marketing and advertising purposes. Google will use the information obtained on behalf of the website operator to evaluate your use of the website, to compile reports on website activity, and to provide the website operator with other services related to website activity and internet usage.
The following information may be collected, among others: IP address, date and time of the page visit, click path, information about the browser and device you use, pages visited, referrer URL (website from which you accessed our website), location data, and purchasing activities. Google may link your data to other data, such as your search history, your personal accounts, your usage data from other devices, and any other data Google has about you.
Your IP address will be shortened by us on our own servers beforehand. This means that Google only receives pseudonymized data.
Google uses technologies such as cookies, web storage in the browser, and tracking pixels that enable an analysis of your website use. The use of cookies or similar technologies is based on your consent in accordance with Section 25 (1) (1) of the Telemedia Act (TDDDG) in conjunction with Article 6 (1) (a) of the GDPR.
Your personal data is processed with your consent on the basis of Art. 6 (1) (a) GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of your consent until the revocation.
The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there. For the USA, the EU Commission has implemented an adequacy decision, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and is thus committed to adhering to European data protection principles. Both Google and US government authorities have access to your data.
Further information on terms of use and data protection can be found at https://policies.google.com/technologies/partner-sites and at https://policies.google.com/privacy?hl=de&gl=de .
Plug-ins and other
Using Google Tag Manager
We use the Google Tag Manager of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
This application manages JavaScript and HTML tags, which are used, in particular, to implement tracking and analysis tools. Data processing serves the purpose of tailoring and optimizing our website to meet your needs.
The Google Tag Manager itself does not store cookies, nor does it process personal data. However, it does allow the activation of additional tags that can collect and process personal data.
Further information on terms of use and data protection can be found here .
We use the Google Tag Manager of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
This application manages JavaScript and HTML tags, which are used, in particular, to implement tracking and analysis tools. Data processing serves the purpose of tailoring and optimizing our website to meet your needs.
The Google Tag Manager itself does not store cookies, nor does it process personal data. However, it does allow the activation of additional tags that can collect and process personal data.
Further information on terms of use and data protection can be found here .
Use of Google reCAPTCHA
We use the reCAPTCHA service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website. This query is used to distinguish between human input and automated machine processing. For this purpose, your input is transmitted to Google and used there. In addition, the IP address and any other data required by Google for the reCAPTCHA service are transmitted to Google. This data is processed by Google within the European Union and may also be transferred to Google LLC servers in the USA. For the USA, the EU Commission has adopted an adequacy decision, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and is thus committed to complying with European data protection principles.
The use of cookies or similar technologies is based on your consent in accordance with Section 25 (1) (s) 1 of the Telemedia Act (TDDDG) in conjunction with Article 6 (1) (a) of the GDPR. Your personal data is processed with your consent in accordance with Article 6 (1) (a) of the GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of your consent until the revocation.
Further information about Google reCAPTCHA and the associated privacy policy can be found at: https://www.google.com/recaptcha/intro/android.html and https://www.google.com/privacy .
Use of Google invisible reCAPTCHAWe use the invisible reCAPTCHA service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
This serves the purpose of distinguishing between input by a human and automated, machine-based processing. In the background, Google collects and analyzes usage data that Invisible reCAPTCHA uses to distinguish regular users from bots. For this purpose, your input is transmitted to Google, where it is further processed. In addition, the IP address and any other data required by Google for the Invisible reCAPTCHA service are transmitted to Google.
This data is processed by Google within the European Union and may also be transferred to Google LLC servers in the USA. For the USA, the EU Commission has issued an adequacy decision, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and is thus committed to complying with European data protection principles.
The use of cookies or similar technologies is based on your consent in accordance with Section 25 (1) (s) 1 of the Telemedia Act (TDDDG) in conjunction with Article 6 (1) (a) of the GDPR. Your personal data is processed with your consent in accordance with Article 6 (1) (a) of the GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of your consent until the revocation.
Further information about Google reC APTCHA and the associated privacy policy can be found at: https://www.google.com/recaptcha/intro/android.html and https://www.google.com/privacy
Use of hCaptcha
We use the hCaptcha service of Intuition Machines Inc. (1065 SW 8th St #704, Miami, FL 33130, USA; “hCaptcha”) on our website as part of order processing.
HCaptcha is used to protect our website from spam and abuse by automated access (bots). By implementing hCaptcha, we ensure that certain actions on our website are only performed by real people, thus ensuring the security and integrity of our online services.
When using hCaptcha, the following data may be collected and processed: user's IP address, information about the device used (e.g. browser and operating system), mouse movements and interactions on the website, length of time spent on the website, user input behavior.
Your data may be transferred to the USA. For the USA, the EU Commission has issued an adequacy decision, the Trans-Atlantic Data Privacy Framework (TADPF). HCaptcha is certified according to the TADPF and is thus committed to complying with European data protection principles.
The use of cookies or similar technologies is based on your consent in accordance with Section 25 (1) (s) 1 of the Telemedia Act (TDDDG) in conjunction with Article 6 (1) (a) of the GDPR. Your personal data is processed with your consent in accordance with Article 6 (1) (a) of the GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of your consent until the revocation.
Further information on data processing and data protection at hCaptcha can be found at https://www.hcaptcha.com/gdpr .
Use of Google Maps
We use the function for embedding Google Maps from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland, "Google") on our website.
This feature enables the visual display of geographical information and interactive maps. Google also collects, processes, and uses data from visitors to the website when they visit pages that incorporate Google Maps.
Your data may also be transferred to the USA. For the USA, the EU Commission has issued an adequacy decision, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and is thus committed to complying with European data protection principles.
The use of cookies or similar technologies is based on your consent in accordance with Section 25 (1) (s) 1 of the Telemedia Act (TDDDG) in conjunction with Article 6 (1) (a) of the GDPR. Your personal data is processed with your consent in accordance with Article 6 (1) (a) of the GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of your consent until the revocation.
For more information about Google's collection and use of data, please see Google's privacy policy at https://www.google.com/privacypolicy.html . There, you can also change your settings in the Privacy Center so that you can manage and protect the data processed by Google.
Rights of data subjects and storage period
Duration of storage
After the contract has been fully processed, the data will initially be stored for the duration of the warranty period, then in accordance with statutory retention periods, in particular those under tax and commercial law, and then deleted after the expiry of the period unless you have consented to further processing and use.
Rights of the data subject
If the legal requirements are met, you are entitled to the following rights under Articles 15 to 20 GDPR: Right to information, to rectification, to erasure, to restriction of processing, to data portability.
Furthermore, according to Art. 21 (1) GDPR, you have the right to object to processing based on Art. 6 (1) (f) GDPR and to processing for direct marketing purposes.
Right to lodge a complaint with the supervisory authority
According to Art. 77 GDPR, you have the right to complain to the supervisory authority if you believe that the processing of your personal data is unlawful.
Right of objection
If the personal data processing listed here is based on our legitimate interest pursuant to Art. 6 (1) (f) GDPR, you have the right to object to this processing at any time with future effect for reasons arising from your particular situation.
Once you have objected, the processing of the data in question will be stopped unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms, or if the processing serves to assert, exercise or defend legal claims.
If personal data is processed for direct marketing purposes, you can object to this processing at any time by notifying us. Once you object, we will stop processing the data in question for direct marketing purposes.
last updated: 22.10.2024