Privacy policy

Privacy Policy

Introduction

The following Privacy Policy is intended to inform you about the types of personal data (hereinafter also referred to simply as ‘data’) that we process, the purposes for which we do so, and the extent of such processing. This Privacy Policy applies to all processing of personal data carried out by us, both in the course of providing our services and, in particular, on our websites, in mobile applications and within external online platforms, such as our social media profiles (hereinafter collectively referred to as the “online offering”).

The terms used are not gender-specific.

Last updated: 23 February 2026

Table of Contents

  • Introduction
  • Data controller
  • Overview of data processing activities
  • Relevant legal bases
  • Security measures
  • Transfer of personal data
  • Data processing in third countries
  • Deletion of data
  • Use of cookies
  • Business services
  • Payment methods
  • Provision of the online service and web hosting
  • Registration, login and user account
  • Blogs and publication media
  • Newsletters and electronic notifications
  • Prize draws and competitions
  • Web analytics, monitoring and optimisation
  • Online marketing
  • Affiliate programmes and affiliate links
  • Social media presence
  • Plugins, embedded functions and content
  • Amendments and updates to the privacy policy
  • Rights of data subjects
  • Definitions

Data Controller / Responsability

OH OH OM ethical sportswear
Jennifer Mustermann
Bellealliancestr. 52
20259 Hamburg
Germany

Email address:
support@ohohom.com 

Overview of data processing

The following overview summarises the types of data processed and the purposes of such processing, and identifies the data subjects.

Types of data processed

  • Personal details.
  • Payment details.
  • Contact details.
  • Content data.
  • Contract details.
  • Usage data.
  • Meta/communication data.

Categories of data subjects

  • Customers.
  • Prospective customers.
  • Communication partners.
  • Users.
  • Participants in prize draws and competitions.
  • Business and contractual partners.

Purposes of processing

  • Provision of contractual services and customer service.
  • Enquiries and communication.
  • Security measures.
  • Direct marketing.
  • Audience measurement.
  • Administrative and organisational procedures.
  • Affiliate tracking.
  • Management and response to enquiries.
  • Organisation of prize draws and competitions.
  • Feedback.
  • Marketing.
  • Profiles containing user-related information.
  • Provision of our online services and user-friendliness.

Relevant legal bases

Below is an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country or ours, depending on where you or we are resident or have our registered office. Should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.

  • Consent (Article 6(1), first sentence, point (a) of the GDPR) – The data subject has given their consent to the processing of personal data relating to them for a specific purpose or for several specific purposes.
  • Performance of a contract and pre-contractual enquiries (Art. 6 (1), first sentence, point (b) of the GDPR) - Processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures taken at the data subject’s request.
  • Legal obligation (Article 6 (1), first sentence, point (c) of the GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Article 6 (1), first sentence, point (f) of the GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

In addition to the data protection provisions of the General Data Protection Regulation, national data protection regulations apply in Germany. These include, in particular, the Act on the Protection against the Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains, in particular, specific provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transfer of data, as well as automated decision-making in individual cases, including profiling. Furthermore, it regulates data processing for the purposes of the employment relationship (Section 26 BDSG), in particular with regard to the establishment, performance or termination of employment relationships, as well as the consent of employees. In addition, state data protection laws of the individual federal states may apply.

Security measures

We implement appropriate technical and organisational measures in accordance with legal requirements, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the varying likelihood and severity of threats to the rights and freedoms of natural persons, in order to ensure a level of security appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input of, disclosure of, and safeguarding of the availability of the data, and its segregation. Furthermore, we have established procedures to ensure that data subjects’ rights are upheld, that data is deleted, and that appropriate action is taken in the event of a data breach. Furthermore, we take the protection of personal data into account right from the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and through privacy-friendly default settings.

SSL encryption (https): To protect the data you submit via our online service, we use SSL encryption. You can recognise such encrypted connections by the prefix https:// in your browser’s address bar.

Transfer of personal data

In the course of our processing of personal data, it may happen that the data is transferred to or disclosed to other bodies, companies, legally independent organisational units or individuals. Recipients of this data may include, for example, service providers commissioned to carry out IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with the statutory requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.

Data processing in third countries

Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where processing takes place in connection with the use of third-party services or the disclosure or transfer of data to other individuals, bodies or organisations, this is done solely in accordance with the relevant legal requirements.

Subject to express consent or where the transfer is required by contract or by law, we process data, or arrange for it to be processed, only in third countries with a recognised level of data protection, where there is a contractual obligation through the European Commission’s so-called standard data protection clauses, where certifications are in place, or where binding internal data protection regulations apply (Articles 44 to 49 of the GDPR, European Commission information page: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de). 

Deletion of data

The data we process is deleted in accordance with statutory requirements as soon as the consent given for its processing is withdrawn or other authorisations cease to apply (e.g. if the purpose for which the data was processed no longer applies or if the data is no longer required for that purpose).

Unless the data is not deleted because it is required for other, legally permissible purposes, its processing is restricted to those purposes. In other words, the data is blocked and not processed for any other purposes. This applies, for example, to data which must be retained for commercial or tax law reasons, or where storage is necessary to establish, exercise or defend legal claims, or to protect the rights of another natural or legal person.

Our privacy notice may also contain further details regarding the retention and deletion of data, which take precedence for the respective processing operations.

Use of cookies

Cookies are small text files or other storage mechanisms that store information on end devices and retrieve information from them. For example, to store the login status in a user account, the contents of a shopping basket in an online shop, the content accessed or the functions used on a website. Cookies may also be used for various other purposes, such as to ensure the functionality, security and user-friendliness of websites, as well as to analyse visitor traffic.

Information on consent: We use cookies in accordance with the relevant legal provisions. We therefore obtain prior consent from users, unless this is not required by law. In particular, consent is not required if the storage and retrieval of information – including cookies – are strictly necessary to provide users with a telemedia service (i.e. our online offering) that they have expressly requested. The revocable consent is clearly communicated to users and includes information on the specific use of cookies.

Information on the legal basis for data protection: The legal basis on which we process users’ personal data using cookies depends on whether we ask users for their consent. If users give their consent, the legal basis for the processing of their data is the consent they have given. Otherwise, the data processed using cookies is processed on the basis of our legitimate interests (e.g. in the commercial operation of our online service and improving its usability) or, where this takes place in the context of fulfilling our contractual obligations, where the use of cookies is necessary to fulfil our contractual obligations. We explain the purposes for which we process cookies in this privacy policy or as part of our consent and processing procedures.

Storage period: With regard to the storage period, a distinction is made between the following types of cookies:

  • Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest once a user has left an online service and closed their device (e.g. browser or mobile application).
  • Persistent cookies: Persistent cookies remain stored even after the device has been switched off. This allows, for example, the login status to be saved or preferred content to be displayed immediately when the user visits a website again. Similarly, user data collected via cookies may be used for audience measurement. Unless we provide users with explicit information regarding the type and storage period of cookies (e.g. when seeking consent), users should assume that cookies are persistent and may be stored for up to two years.

General information on withdrawal of consent and objection (opt-out): Users may withdraw the consent they have given at any time and may also object to the processing of their data in accordance with the legal provisions set out in Article 21 of the GDPR (further information on the right to object is provided in this privacy policy). Users may also exercise their right to object via their browser settings.

Further information on processing procedures, methods and services:

  • Processing of cookie data on the basis of consent: We use a cookie consent management procedure, within the framework of which users’ consent to the use of cookies – or, more specifically, to the processing activities and providers specified in the cookie consent management procedure – is obtained and can be managed and withdrawn by users. In this context, the declaration of consent is stored so that the user does not have to be asked for consent again and so that consent can be demonstrated in accordance with the legal obligation. Storage may take place on the server and/or in a cookie (a so-called ‘opt-in’ cookie, or using comparable technologies) in order to be able to associate the consent with a user or their device. Subject to specific information provided by the providers of cookie management services, the following applies: Consent may be stored for up to two years. In this process, a pseudonymous user identifier is generated and stored alongside the time of consent, details of the scope of consent (e.g. which categories of cookies and/or service providers) and the browser, operating system and end device used.

Business Services

We process data relating to our contractual and business partners, e.g. customers and prospective customers (collectively referred to as ‘contractual partners’), in the context of contractual and similar legal relationships, as well as associated measures and in the context of communication with contractual partners (or at the pre-contractual stage), e.g. to respond to enquiries.

We process this data in order to fulfil our contractual obligations. These include, in particular, the obligations to provide the agreed services, any obligations to update the data, and to remedy any breaches of warranty or other service disruptions. Furthermore, we process the data to safeguard our rights and for the purposes of administrative tasks associated with these obligations, as well as for the organisation of our business. In addition, we process the data on the basis of our legitimate interests in the proper and sound management of our business, as well as in security measures to protect our contractual partners and our business operations from misuse, risks to their data, confidential information, details and rights (e.g. involving telecommunications, transport and other ancillary services, as well as subcontractors, banks, tax and legal advisers, payment service providers or tax authorities). Within the framework of applicable law, we only disclose the data of contractual partners to third parties to the extent that this is necessary for the aforementioned purposes or to fulfil legal obligations. Contractual partners are informed about other forms of processing, e.g. for marketing purposes, within the framework of this privacy policy.

We inform our contractual partners of the data required for the aforementioned purposes either before or during the data collection process, for example in online forms, by means of specific markings (e.g. colours) or symbols (e.g. asterisks or similar), or in person.

We delete the data once statutory warranty obligations and similar obligations have expired, i.e. generally after 4 years, unless the data is stored in a customer account, for example, for as long as it must be retained for statutory archiving purposes (e.g. for tax purposes, usually 10 years). We delete data disclosed to us by the contractual partner in the context of a contract in accordance with the terms of the contract, generally upon completion of the contract.

Where we use third-party providers or platforms to provide our services, the terms and conditions and privacy policies of the respective third-party providers or platforms shall apply to the relationship between users and those providers.

Customer account

Contractual partners may create an account within our online service (e.g. a customer or user account, hereinafter referred to as a “customer account”). Where the registration of a customer account is required, contractual partners will be informed of this, as well as of the details required for registration. Customer accounts are not public and cannot be indexed by search engines. As part of the registration process, as well as subsequent logins and use of the customer account, we store customers’ IP addresses along with the times of access in order to verify the registration and to prevent any misuse of the customer account.

If customers have closed their account, the data relating to that account will be deleted, unless retention is required for legal reasons. It is the customers’ responsibility to back up their data once the account has been closed.

Shop and E-commerce

We process our customers’ data to enable them to select, purchase or order the chosen products, goods and related services, as well as to facilitate payment and delivery or fulfilment. Where necessary for the fulfilment of an order, we engage service providers – in particular postal, freight and delivery companies – to carry out the delivery or fulfilment on behalf of our customers. We use the services of banks and payment service providers to process payment transactions. The required details are clearly marked as such during the ordering process or similar purchase procedure and include the information needed for delivery, provision of goods or services and billing, as well as contact details to enable us to get in touch if necessary.

Events and functions

We process the data of participants in the events, functions and similar activities that we offer or organise (hereinafter collectively referred to as “participants” and “events”) in order to enable them to take part in the events and make use of the services or promotions associated with their participation.

Where we process health-related data, religious, political or other special categories of data in this context, this is done in a transparent manner (e.g. in the case of themed events, or where it serves the purposes of healthcare, safety, or is carried out with the consent of the data subjects).

The required information is identified as such when concluding a contract, order or similar agreement and comprises the details necessary for the provision of services and invoicing, as well as contact details to enable any necessary consultations. Where we gain access to information relating to end customers, employees or other individuals, we process this in accordance with statutory and contractual requirements.

  • Types of data processed: Personal details (e.g. names, addresses); payment details (e.g. bank details, invoices, payment history); contact details (e.g. email, telephone numbers); contract details (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses).
  • Data subjects: customers; prospective customers; business and contractual partners.
  • Purposes of processing: provision of contractual services and customer service; security measures; contact enquiries and communication; office and organisational procedures; administration and response to enquiries.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR); legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); legal obligation (Art. 6(1), first sentence, point (c) of the GDPR).

Payment procedures

In the context of contractual and other legal relationships, in accordance with statutory obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and, to this end, engage banks and credit institutions as well as other service providers (collectively, ‘payment service providers’).

The data processed by the payment service providers includes personal details, such as name and address; bank details, such as account numbers or credit card numbers; passwords, TANs and checksums; as well as information relating to the contract, the amount and the recipient. This information is required to carry out the transactions. However, the data entered is processed and stored solely by the payment service providers. This means that we do not receive any account- or credit card-related information, but only information confirming or rejecting the payment. In some circumstances, the data may be transferred by the payment service providers to credit reference agencies. The purpose of this transfer is to verify identity and creditworthiness. In this regard, we refer you to the terms and conditions and privacy policies of the payment service providers.

Payment transactions are subject to the terms and conditions and privacy policies of the respective payment service providers, which are available on their respective websites or within the transaction applications. We also refer you to these for further information and for exercising your rights of withdrawal, access and other data subject rights.

  • Types of data processed: Personal details (e.g. names, addresses); payment details (e.g. bank details, invoices, payment history); contract details (e.g. subject matter of the contract, term, customer category); Usage data (e.g. websites visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses); contact details (e.g. email, telephone numbers).
  • Data subjects: Customers; prospective customers.
  • Purposes of processing: Provision of contractual services and customer service.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR); legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).

Further information on processing procedures, methods and services:

  • Apple Pay: payment processing services; service provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; website: https://www.apple.com/de/apple-pay/; privacy policy: https://www.apple.com/legal/privacy/de-ww/.
  • Giropay: Payment processing services; Service provider: giropay GmbH, An der Welle 4, 60322 Frankfurt, Germany; Website: https://www.giropay.de; Privacy policy: https://www.giropay.de/rechtliches/datenschutzerklaerung/.
  • Google Pay: Payment processing services; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://pay.google.com/intl/de_de/about/; privacy policy: https://policies.google.com/privacy.
  • Mastercard: Payment processing services; Service provider: Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium; Website: https://www.mastercard.de/de-de.html; Privacy policy: https://www.mastercard.de/de-de/datenschutz.html.
  • PayPal: Payment processing services (e.g. PayPal, PayPal Plus, Braintree); Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg; website: https://www.paypal.com/de; privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
  • Visa: Payment processing services; Service provider: Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, UK; Website: https://www.visa.de; Privacy policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.

Provision of the online service and web hosting

In order to provide our online services securely and efficiently, we use the services of web hosting providers, from whose servers (or servers managed by them) the online services can be accessed. For these purposes, we may utilise infrastructure and platform services, computing capacity, storage space and database services, as well as security and technical maintenance services.

The data processed in connection with the provision of the hosting service may include all information relating to users of our online service that is generated in the course of their use of the service and their communications. This typically includes the IP address, which is necessary to deliver the content of online services to browsers, as well as all data entered within our online service.

Types of data processed: Content data (e.g. entries in online forms); usage data (e.g. web pages visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses).

  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of our online services and user-friendliness; provision of contractual services and customer service.
  • Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Further information on processing procedures, methods and services:

  • Collection of access data and log files:
    We, or our hosting providers, automatically collect data relating to each access to our online service (so-called server log files).
    These server log files include, in particular, the name and URL of the file accessed, the date and time of access, the amount of data transferred, confirmation of a successful access, the browser type and version, the operating system used, the referrer URL (the page visited previously), the IP address of the requesting device and the requesting internet service provider.& nbsp;This data is processed on the basis of our legitimate interests in accordance with Article 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring the security and stability of our online service, defending against attacks (e.g. DDoS attacks), analysing errors, preventing misuse and fraud, and optimising our service from a technical perspective.  Log file data is generally stored for a maximum of 30 days and is subsequently deleted or anonymised. Data may only be stored for longer if this is necessary to investigate specific security incidents or to enforce legal claims.

  • ALL-INKL.COM – Neue Medien Münnich: Services relating to the provision of IT infrastructure and associated services (e.g. storage space and computing capacity); Service provider: ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany; Website: https://all-inkl.com; Privacy Policy: https://all-inkl.com/datenschutzinformationen/; Data Processing Agreement: A data processing agreement has been concluded with the provider in accordance with Article 28 of the GDPR. Server location: Germany.

  • Shopify: Shop system and technical platform for operating our online shop; Service provider: Shopify International Limited, 2nd Floor, 1–2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland; Parent company: Shopify Inc., 151 O’Connor Street, Ground Floor, Ottawa, Ontario, K2P 2L8, Canada; Website: https://www.shopify.com/de; Privacy policy: https://www.shopify.com/de/legal/datenschutz; Data processing under a data processing agreement in accordance with Article 28 of the GDPR. Data transfers to third countries are carried out in accordance with legal requirements, in particular using the European Commission’s standard contractual clauses.

Registration, login and user account

Users can create a user account. During the registration process, users are informed of the required mandatory details, which are processed for the purpose of providing the user account on the basis of the fulfilment of contractual obligations. The data processed includes, in particular, login details (username, password and an email address).

When you use our registration and login functions, as well as when you use your user account, we store your IP address and the time of the respective user action. This data is stored on the basis of our legitimate interests, as well as those of users, in protecting against misuse and other unauthorised use. This data is not, as a rule, disclosed to third parties, unless this is necessary to pursue our claims or there is a legal obligation to do so.

Users may be informed by email about matters relevant to their user account, such as technical changes.

  • Types of data processed: Personal details (e.g. names, addresses); contact details (e.g. email addresses, telephone numbers); content data (e.g. entries in online forms); meta/communication data (e.g. device information, IP addresses).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of contractual services and customer service; security measures; administration and response to enquiries.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR); legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).

Further information on processing procedures, methods and services:

  • Deletion of data following termination: Once users have closed their user accounts, their data relating to that account will be deleted, subject to any statutory authorisation, obligation or the user’s consent.
  • No obligation to retain data: It is the users’ responsibility to back up their data upon termination of the contract before the end of the contract period. We are entitled to irrevocably delete all of the user’s data stored during the term of the contract.

Blogs and publication media

We use blogs or similar means of online communication and publication (hereinafter referred to as ‘publication medium’). Readers’ data is processed for the purposes of the publication medium only to the extent necessary for its presentation and for communication between authors and readers, or for security reasons. For all other matters, please refer to the information on the processing of visitors to our publication medium set out in this privacy policy.

  • Types of data processed: Personal details (e.g. names, addresses); contact details (e.g. email addresses, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); Meta/communication data (e.g. device information, IP addresses).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of contractual services and customer service; feedback (e.g. collection of feedback via online forms).
  • Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR); legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).

Newsletters and electronic notifications

We send out newsletters, emails and other electronic notifications (hereinafter referred to as “newsletters”) only with the recipients’ consent or where permitted by law. Where the content of a newsletter is specifically described as part of the subscription process, this content forms the basis for the user’s consent. In addition, our newsletters contain information about our services and our organisation.

To subscribe to our newsletters, you generally only need to provide your email address. However, we may ask you to provide a name, so that we can address you personally in the newsletter, or further details, should these be necessary for the purposes of the newsletter.

Double opt-in procedure: Subscription to our newsletter generally takes place via a so-called double opt-in procedure. This means that, after subscribing, you will receive an email asking you to confirm your subscription. This confirmation is necessary to ensure that nobody can subscribe using someone else’s email address. Subscriptions to the newsletter are logged in order to provide evidence of the subscription process in accordance with legal requirements. This includes storing the time of subscription and confirmation, as well as the IP address. Any changes to your data stored with the mailing service provider are also logged.

Deletion and restriction of processing: We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to provide evidence of consent that was previously given. The processing of this data is limited to the purpose of potentially defending against claims. An individual request for erasure may be made at any time, provided that the prior existence of consent is confirmed at the same time. In the event of obligations to permanently comply with objections, we reserve the right to store the email address solely for this purpose in a block list.

The logging of the registration process is carried out on the basis of our legitimate interests for the purpose of verifying that it has been carried out correctly. Where we engage a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure delivery system.

Notes on legal bases: Newsletters are sent on the basis of the recipients’ consent or, where consent is not required, on the basis of our legitimate interests in direct marketing, provided that this is permitted by law, e.g. in the case of marketing to existing customers. Where we engage a service provider to send emails, this is done on the basis of our legitimate interests in efficient and secure delivery. The registration process is recorded on the basis of our legitimate interests in order to demonstrate that it was carried out in accordance with the law.

Contents:

Information about us, our services, promotions and offers.

  • Types of data processed: Master data (e.g. names, addresses); contact details (e.g. email, telephone numbers); meta/communication data (e.g. device information, IP addresses); usage data (e.g. websites visited, interest in content, access times).
  • Data subjects: Communication partners.
  • Purposes of processing: Direct marketing (e.g. by email or post).
  • Legal bases: Consent (Art. 6(1)(a) GDPR); Legitimate interests (Art. 6(1)(f) GDPR).
  • Right to object (opt-out): You may unsubscribe from our newsletter at any time, i.e. withdraw your consent or object to receiving further issues. You will find a link to unsubscribe from the newsletter either at the end of each newsletter or you may use one of the contact options listed above, preferably by email.

Further information on data processing procedures, methods and services:

  • Measuring open and click-through rates: The newsletters contain a so-called ‘web beacon’, i.e. a pixel-sized file which is retrieved from our server – or, if we use a mailing service provider, from their server – when the newsletter is opened. As part of this retrieval, technical information – such as details about your browser and system – as well as your IP address and the time of retrieval are initially collected. This information is used to improve our newsletter technically, based on the technical data or the target groups and their reading behaviour, determined by their location (which can be identified using the IP address) or the times at which the newsletter is accessed. This analysis also includes determining whether the newsletters are opened and when they are opened.

Prize draws and competitions

We process the personal data of participants in prize draws and competitions only in compliance with the relevant data protection regulations, insofar as such processing is contractually required for the organisation and organising and administering the prize draw, the participants have consented to the processing, or the processing serves our legitimate interests (e.g. in ensuring the security of the prize draw or protecting our interests against misuse through the possible collection of IP addresses when prize draw entries are submitted).

If participants’ entries are published in connection with the prize draws (e.g. as part of a vote or the presentation of entries or winners, or in reports on the prize draw), we would like to point out that participants’ names may also be published in this context. Participants may object to this at any time.

If the prize draw takes place on an online platform or social network (e.g. Facebook or Instagram, hereinafter referred to as an “online platform”), the terms of use and privacy policies of the respective platforms shall also apply. In such cases, we would like to point out that we are responsible for the information provided by participants in connection with the prize draw and that any enquiries regarding the prize draw should be addressed to us.

Participants’ data will be deleted as soon as the prize draw or competition has ended and the data is no longer required to inform the winners or because enquiries regarding the prize draw are to be expected. In principle, participants’ data will be deleted no later than 6 months after the end of the prize draw. Data relating to the winners may be retained for longer, for example, to answer enquiries about the prizes or to fulfil the prize obligations; in which case the retention period depends on the nature of the prize and, for example, may be up to three years for goods or services, to enable us to deal with warranty claims. Furthermore, participants’ data may be stored for longer, for example in the form of reports on the prize draw in online and offline media.

Where data has also been collected for other purposes as part of the prize draw, its processing and retention period are governed by the privacy notice relating to that use (e.g. in the case of subscribing to a newsletter as part of a prize draw).

  • Types of data processed: Personal details (e.g. names, addresses); content data (e.g. entries in online forms).
  • Data subjects: Participants in prize draws and competitions.
  • Purposes of processing: Organisation of prize draws and competitions.
  • Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR).

Web analytics, monitoring and optimisation

Web analytics (also referred to as ‘reach measurement’) is used to analyse visitor traffic to our online platform and may include pseudonymous data on visitors’ behaviour, interests or demographic information, such as age or gender. With the help of reach analysis, we can, for example, identify at what times our online service, its functions or content are used most frequently, or encourage repeat visits. We can also identify which areas require optimisation.

In addition to web analytics, we may also use testing procedures to, for example, test and optimise different versions of our online offering or its components.

Unless otherwise stated below, profiles – i.e. data aggregated to reflect a usage session – may be created for these purposes, and information may be stored in a browser or on a device and retrieved from it. The data collected includes, in particular, the web pages visited and the elements used on them, as well as technical details such as the browser and computer system used, and information on usage times. Where users have given their consent to the collection of their location data, either to us or to the providers of the services we use, location data may also be processed.

Users’ IP addresses are also stored. However, we use an IP masking process (i.e. pseudonymisation by truncating the IP address) to protect users. Generally speaking, no personally identifiable data (such as email addresses or names) is stored in the context of web analytics, A/B testing and optimisation; instead, pseudonyms are used. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective processes.

Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for the processing of data is consent. Otherwise, users’ data is processed on the basis of our legitimate interests (i.e. an interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g. webpages visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Audience measurement (e.g. access statistics, identification of returning visitors); profiles containing user-related information (creation of user profiles).
  • Security measures: IP masking (pseudonymisation of the IP address).
  • Legal bases: Consent (Art. 6(1), first sentence, point (a) of the GDPR); legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).

Further information on processing procedures, methods and services:

  • Google Analytics: web analytics, audience measurement and measurement of user flows; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com/intl/de/about/analytics/; Privacy policy: https://policies.google.com/privacy; Further information: Types of processing and data processed: https://privacy.google.com/businesses/adsservices; Data processing terms for Google advertising products and standard contractual clauses for data transfers to third countries: https://business.safety.google/adsprocessorterms.
  • Klar (Klar Insights GmbH) / Klar Attribution:  We use the services of Klar (Klar Insights GmbH, Marktstr. 18, 80802 Munich, Germany) on our website. Klar collects, processes and stores data on this website and its subpages for the purposes of audience measurement and statistical analysis on our behalf. This data collection is carried out on the following legal basis: where the user has given their consent in accordance with Article 6(1), first sentence, point (a) of the GDPR and Section 25(1), first sentence of the TTDSG, the data to be processed is collected on a user-specific basis. Different cookies are used for the various types of data collection mentioned above to ensure the respective type of collection takes place. Cookie Opt-out To opt out of the use of Klar in general, please use this link. This will set a cookie named “do_not_track” from the domain “pascal.sh”. Please do not delete this, as otherwise we cannot guarantee that you will not be tracked by Klar. Information on data protection and data usage by Klar can be found on the following website: https://www.getklar.com/data-protection

Online marketing

We process personal data for the purposes of online marketing, which may include, in particular, the marketing of advertising space or the display of advertising and other content (collectively referred to as ‘content’) based on users’ potential interests, as well as the measurement of its effectiveness.

For these purposes, so-called user profiles are created and stored in a file (known as a ‘cookie’) or similar methods are used to store information about the user that is relevant to the display of the aforementioned content. This information may include, for example, content viewed, websites visited, online networks used, as well as communication partners and technical details such as the browser and computer system used, and information on usage times and functions utilised. Where users have consented to the collection of their location data, this may also be processed.

Users’ IP addresses are also stored. However, we use available IP masking methods (i.e. pseudonymisation by truncating the IP address) to protect users. Generally, no plaintext user data (such as email addresses or names) is stored as part of online marketing procedures; instead, pseudonyms are used. This means that neither we nor the providers of the online marketing procedures know the actual identity of the users, but only the information stored in their profiles.

The information in the profiles is usually stored in cookies or by means of similar methods. These cookies can generally also be read later on other websites that use the same online marketing service, analysed for the purpose of displaying content, supplemented with further data, and stored on the server of the online marketing service provider.

In exceptional cases, specific data may be linked to user profiles. This is the case, for example, when users are members of a social network whose online marketing methods we utilise, and the network links users’ profiles to the aforementioned information. Please note that users may enter into additional agreements with these providers, for example by giving their consent during the registration process.

In principle, we only have access to aggregated information regarding the success of our advertisements. However, as part of so-called conversion tracking, we can analyse which of our online marketing methods have led to a so-called conversion, i.e. for example, the conclusion of a contract with us. Conversion tracking is used solely to analyse the success of our marketing measures.

Unless otherwise stated, please assume that the cookies used will be stored for a period of two years.

Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for the processing of data is consent. Otherwise, users’ data is processed on the basis of our legitimate interests (i.e. our interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g. websites visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Marketing; Profiles containing user-related information (creation of user profiles).
  • Security measures: IP masking (pseudonymisation of the IP address).
  • Legal bases: Consent (Art. 6(1), first sentence, point (a) of the GDPR); Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
  • Option to object (opt-out): We refer you to the privacy policies of the respective providers and the options to object (known as ‘opt-out’) specified by them. If no explicit opt-out option has been provided, you may disable cookies in your browser settings. However, this may restrict certain functions of our online service. We therefore also recommend the following opt-out options, which are summarised and organised by region: a) Europe: https://www.youronlinechoices.eu. b) Canada: https://www.youradchoices.ca/choices. c) USA: https://www.aboutads.info/choices. d) Worldwide: https://optout.aboutads.info.

Affiliate programmes and affiliate links

We incorporate so-called affiliate links or other references (which may include, for example, search boxes, widgets or discount codes) to the offers and services of third-party providers into our online platform (collectively referred to as “affiliate links”). If users follow the affiliate links or subsequently take up the offers, we may receive a commission or other benefits from these third-party providers (collectively referred to as ‘commission’).

In order to track whether users have taken up the offers via an affiliate link we have used, it is necessary for the relevant third-party providers to be informed that users have followed an affiliate link included within our online service. The linking of affiliate links to the relevant transactions or other actions (e.g. purchases) serves solely the purpose of commission settlement and is deleted as soon as it is no longer required for that purpose.

For the purposes of the aforementioned assignment of affiliate links, the affiliate links may be supplemented with certain values which form part of the link or may otherwise be stored, for example in a cookie. These values may include, in particular, the referring website (referrer), the time, an online identifier of the operator of the website on which the affiliate link was located, an online identifier of the relevant offer, the type of link used, the type of offer and an online identifier of the user.

Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for the processing of data is consent. Furthermore, the use of such third-party providers may form part of our (pre-)contractual services, provided that the use of these third-party providers has been agreed within this context. Otherwise, users’ data is processed on the basis of our legitimate interests (i.e. an interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. webpages visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Affiliate tracking.
  • Legal bases: Consent (Article 6(1)(a) of the GDPR); performance of a contract and pre-contractual enquiries (Article 6(1)(b) of the GDPR); legitimate interests (Article 6(1)(f) of the GDPR).

Social media presence

We maintain an online presence on social media platforms and, in this context, process users’ data in order to communicate with users active on these platforms or to provide information about us.

We would like to point out that this may involve the processing of users’ data outside the European Union. This may entail risks for users, as it could, for example, make it more difficult to enforce their rights.

Furthermore, users’ data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created on the basis of users’ behaviour and the interests derived from it. These usage profiles can in turn be used, for example, to display advertisements both within and outside the networks that are presumed to correspond to users’ interests. For these purposes, cookies are usually stored on users’ computers, in which their usage behaviour and interests are recorded. Furthermore, data may also be stored in the user profiles regardless of the devices used by the users (in particular if the users are members of the respective platforms and are logged in to them).

For a detailed description of the respective forms of processing and the options for objecting (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks.

We would also like to point out that, in the case of requests for information and the exercise of data subjects’ rights, these can most effectively be exercised with the service providers. Only the service providers have access to users’ data in each case and can take appropriate action and provide information directly. Should you nevertheless require assistance, you may contact us.

  • Types of data processed: Contact details (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Contact enquiries and communication; feedback (e.g. collecting feedback via online forms); marketing.
  • Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Further information on processing procedures, methods and services:

  • Instagram: social network;
    service provider: Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA; website: https://www.instagram.com;
    privacy policy: https://instagram.com/about/legal/privacy.
  • Facebook Pages: Profiles within the Facebook social network – We are jointly responsible with Facebook Ireland Ltd. for the collection (but not the further processing) of data relating to visitors to our Facebook page (known as a ‘fan page’). This data includes information on the types of content that users view or interact with, or the actions they take (see ‘Things you and others do and share’ in the Facebook Data Policy: https://www.facebook.com/policy), as well as information about the devices used by users (e.g. IP addresses, operating system, browser type, language settings, cookie data; see ‘Device Information’ in the Facebook Data Policy: https://www.facebook.com/policy). As explained in the Facebook Data Policy under ‘How do we use this information?’, Facebook also collects and uses information to provide analytics services, known as ‘Page Insights’, to page administrators, so that they can gain insights into how people interact with their pages and the content associated with them. We have entered into a specific agreement with Facebook (“Information on Page Insights”,  https://www.facebook.com/legal/terms/page_controller_addendum), which sets out, in particular, the security measures Facebook must observe and in which Facebook has agreed to fulfil data subjects’ rights (i.e. users can, for example, submit requests for information or erasure directly to Facebook). Users’ rights (in particular the rights to access, erasure, objection and to lodge a complaint with the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the “Page Insights Information” (https://www.facebook.com/legal/terms/information_about_page_insights_data);
    service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; website:
    https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy; Standard contractual clauses (guaranteeing data protection standards when processing in third countries): https://www.facebook.com/legal/EU_data_transfer_addendum;
    Further information: Joint controller agreement: https://www.facebook.com/legal/terms/information_about_page_insights_data.
  • YouTube: Social network and video platform; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Privacy policy: https://policies.google.com/privacy; Opt-out option: https://adssettings.google.com/authenticated.

Plugins, embedded functions and content

We incorporate functional and content elements into our online service which are sourced from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include, for example, graphics, videos or city maps (hereinafter collectively referred to as “content”).

The integration always requires the third-party providers of this content to process users’ IP addresses, as they would be unable to send the content to users’ browsers without them. The IP address is therefore necessary for the display of this content or these functions. We endeavour to use only content where the respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as ‘web beacons’) for statistical or marketing purposes. These ‘pixel tags’ enable information, such as visitor traffic on the pages of this website, to be analysed. This pseudonymous information may also be stored in cookies on the user’s device and may include, amongst other things, technical information about the browser and operating system, referring websites, the time of the visit and further details regarding the use of our online service; it may also be linked to such information from other sources.

Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for the processing of data is consent. Otherwise, users’ data is processed on the basis of our legitimate interests (i.e. our interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: usage data (e.g. websites visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses); personal details (e.g. names, addresses); contact details (e.g. email, telephone numbers); content data (e.g. entries in online forms).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of our online services and user-friendliness; provision of contractual services and customer service.
  • Legal bases: Consent (Art. 6(1), first sentence, point (a) of the GDPR); performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR); legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).

Further information on processing operations, procedures and services:

  • Google Fonts: We integrate fonts (“Google Fonts”) from the provider Google, whereby users’ data is used solely for the purpose of displaying the fonts in the user’s browser. This integration is based on our legitimate interests in the technically secure, maintenance-free and efficient use of fonts, their consistent display, and in compliance with any licence restrictions relating to their integration; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://fonts.google.com/; privacy policy: https://policies.google.com/privacy.
  • Google Maps: We integrate maps from the “Google Maps” service provided by Google. The data processed may include, in particular, users’ IP addresses and location data; however, this data is not collected without their consent (which is usually given via the settings on their mobile devices); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://cloud.google.com/maps-platform;
    privacy policy: https://policies.google.com/privacy;
    Opt-out option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of adverts: https://adssettings.google.com/authenticated
  • YouTube videos: Video content;
    Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://www.youtube.com;
    Privacy policy: https://policies.google.com/privacy; Opt-out option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of adverts: https://adssettings.google.com/authenticated.

Changes to and updates of the Privacy Policy

We ask that you check the content of our Privacy Policy regularly. We will amend the Privacy Policy as soon as changes to the data processing activities we carry out make this necessary. We will inform you as soon as the changes require any action on your part (e.g. consent) or any other individual notification.

Where we provide addresses and contact details of companies and organisations in this privacy policy, please note that these addresses may change over time; we therefore ask that you check the details before making contact.

Rights of data subjects

As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:

  • Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you carried out on the basis of Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. Where personal data relating to you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
  • Right of access: You have the right to request confirmation as to whether the relevant data is being processed, and to obtain access to this data, as well as further information and a copy of the data in accordance with the statutory requirements.
  • Right to rectification: In accordance with the statutory provisions, you have the right to request that data relating to you be completed or that any inaccurate data relating to you be rectified.
  • Right to erasure and restriction of processing: In accordance with the statutory provisions, you have the right to request that data relating to you be erased without delay or, alternatively, in accordance with the statutory provisions, to request a restriction on the processing of such data.
  • Right to data portability: You have the right, in accordance with the statutory provisions, to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transferred to another data controller.
  • Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place where the alleged infringement occurred, if you consider that the processing of your personal data infringes the provisions of the GDPR.

Definitions of Terms

This section provides an overview of the terms used in this privacy policy. Many of these terms are taken from the law and are defined, in particular, in Article 4 of the GDPR. The legal definitions are binding. The explanations below, however, are intended primarily to aid understanding. The terms are listed in alphabetical order.

  • Affiliate tracking: As part of affiliate tracking, links are logged which are used by linking websites to direct users to websites offering products or other services. The operators of the respective linking websites may receive a commission if users follow these so-called affiliate links and subsequently take advantage of the offers (e.g. purchase goods or use services). For this to work, providers need to be able to track whether users who are interested in specific offers subsequently take advantage of them as a result of the affiliate links. It is therefore necessary for affiliate links to function that they are supplemented with certain values, which either become part of the link or are stored elsewhere, for example in a cookie. These values include, in particular, the referring website (referrer), the time, an online identifier for the operator of the website on which the affiliate link was located, an online identifier for the relevant offer, an online identifier for the user, as well as tracking-specific values such as, for example, advertising material ID, partner ID and categorisations.
  • Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); a natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Profiles containing user-related information: The processing of ‘profiles containing user-related information’, or ‘profiles’ for short, encompasses any form of automated processing of personal data that involves using such personal data to analyse, evaluate or predict certain personal aspects relating to a natural person (depending on the nature of the profiling, this may include various types of information concerning demographics, behaviour and interests, such as interaction with websites and their content, etc.), or to predict them (e.g. interests in specific content or products, clicking behaviour on a website or location). Cookies and web beacons are frequently used for profiling purposes.
  • Audience measurement: Audience measurement (also known as web analytics) is used to analyse visitor traffic to an online service and may include the behaviour or interests of visitors in relation to specific information, such as website content. With the help of reach analysis, website owners can, for example, identify at what times visitors access their website and what content they are interested in. This enables them, for instance, to better tailor the website’s content to the needs of their visitors. For the purposes of reach analysis, pseudonymous cookies and web beacons are frequently used to identify returning visitors and thus obtain more accurate analyses of the use of an online service.
  • Data controller: The term ‘data controller’ refers to the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: ‘Processing’ means any operation or set of operations which is carried out on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, be it collection, analysis, storage, transmission or erasure.