Privacy Policy

1. An overview of data protection

General information

The fol­lo­wing infor­ma­ti­on will pro­vi­de you with an easy to navi­ga­te over­view of what will hap­pen with your per­so­nal data when you visit this web­site. The term “per­so­nal data” com­pri­ses all data that can be used to per­so­nal­ly iden­ti­fy you. For detail­ed infor­ma­ti­on about the sub­ject mat­ter of data pro­tec­tion, plea­se con­sult our Data Pro­tec­tion Decla­ra­ti­on, which we have included beneath this copy.

Data recording on this website

Who is the responsible party for the recording of data on this website (i.e., the “controller”)?

The data on this web­site is pro­ces­sed by the ope­ra­tor of the web­site, who­se cont­act infor­ma­ti­on is available under sec­tion “Infor­ma­ti­on about the respon­si­ble par­ty (refer­red to as the “con­trol­ler” in the GDPR)” in this Pri­va­cy Policy.

How do we record your data?

We coll­ect your data as a result of your sha­ring of your data with us. This may, for ins­tance be infor­ma­ti­on you enter into our cont­act form.

Other data shall be recor­ded by our IT sys­tems auto­ma­ti­cal­ly or after you con­sent to its recor­ding during your web­site visit. This data com­pri­ses pri­ma­ri­ly tech­ni­cal infor­ma­ti­on (e.g., web brow­ser, ope­ra­ting sys­tem, or time the site was acces­sed). This infor­ma­ti­on is recor­ded auto­ma­ti­cal­ly when you access this website.

What are the purposes we use your data for?

A por­ti­on of the infor­ma­ti­on is gene­ra­ted to gua­ran­tee the error free pro­vi­si­on of the web­site. Other data may be used to ana­ly­ze your user pat­terns. If con­tracts can be con­cluded or initia­ted via the web­site, the trans­mit­ted data will also be pro­ces­sed for con­tract offers, orders or other order enquiries.

What rights do you have as far as your information is concerned?

You have the right to recei­ve infor­ma­ti­on about the source, reci­pi­ents, and pur­po­ses of your archi­ved per­so­nal data at any time wit­hout having to pay a fee for such dis­clo­sures. You also have the right to demand that your data are rec­ti­fied or era­di­ca­ted. If you have con­sen­ted to data pro­ces­sing, you have the opti­on to revo­ke this con­sent at any time, which shall affect all future data pro­ces­sing. Moreo­ver, you have the right to demand that the pro­ces­sing of your data be rest­ric­ted under cer­tain cir­cum­s­tances. Fur­ther­mo­re, you have the right to log a com­plaint with the com­pe­tent super­vi­sing agency.

Plea­se do not hesi­ta­te to cont­act us at any time if you have ques­ti­ons about this or any other data pro­tec­tion rela­ted issues.

Analysis tools and tools provided by third parties

The­re is a pos­si­bi­li­ty that your brow­sing pat­terns will be sta­tis­ti­cal­ly ana­ly­zed when your visit this web­site. Such ana­ly­ses are per­for­med pri­ma­ri­ly with what we refer to as ana­ly­sis programs.

For detail­ed infor­ma­ti­on about the­se ana­ly­sis pro­grams plea­se con­sult our Data Pro­tec­tion Decla­ra­ti­on below.

2. Hosting

We are hos­ting the con­tent of our web­site at the fol­lo­wing provider:

External Hosting

This web­site is hos­ted extern­al­ly. Per­so­nal data coll­ec­ted on this web­site are stored on the ser­vers of the host. The­se may include, but are not limi­t­ed to, IP addres­ses, cont­act requests, meta­da­ta and com­mu­ni­ca­ti­ons, con­tract infor­ma­ti­on, cont­act infor­ma­ti­on, names, web page access, and other data gene­ra­ted through a web site.

The exter­nal hos­ting ser­ves the pur­po­se of ful­fil­ling the con­tract with our poten­ti­al and exis­ting cus­to­mers (Art. 6(1)(b) GDPR) and in the inte­rest of secu­re, fast, and effi­ci­ent pro­vi­si­on of our online ser­vices by a pro­fes­sio­nal pro­vi­der (Art. 6(1)(f) GDPR). If appro­pria­te con­sent has been obtai­ned, the pro­ces­sing is car­ri­ed out exclu­si­ve­ly on the basis of Art. 6 (1)(a) GDPR and § 25 (1) TDDDG, inso­far the con­sent includes the sto­rage of coo­kies or the access to infor­ma­ti­on in the user’s end device (e.g., device fin­ger­prin­ting) within the mea­ning of the TDDDG. This con­sent can be revo­ked at any time.

Our host(s) will only pro­cess your data to the ext­ent neces­sa­ry to ful­fil its per­for­mance obli­ga­ti­ons and to fol­low our ins­truc­tions with respect to such data.

We are using the fol­lo­wing host(s):

Meta­net
Josef­stras­se 218
8005 Zürich
Schweiz

Data processing

We have con­cluded a data pro­ces­sing agree­ment (DPA) for the use of the abo­ve-men­tio­ned ser­vice. This is a con­tract man­da­ted by data pri­va­cy laws that gua­ran­tees that they pro­cess per­so­nal data of our web­site visi­tors only based on our ins­truc­tions and in com­pli­ance with the GDPR.

3. General information and mandatory information

Data protection

The ope­ra­tors of this web­site and its pages take the pro­tec­tion of your per­so­nal data very serious­ly. Hence, we hand­le your per­so­nal data as con­fi­den­ti­al infor­ma­ti­on and in com­pli­ance with the sta­tu­to­ry data pro­tec­tion regu­la­ti­ons and this Data Pro­tec­tion Declaration.

When­ever you use this web­site, a varie­ty of per­so­nal infor­ma­ti­on will be coll­ec­ted. Per­so­nal data com­pri­ses data that can be used to per­so­nal­ly iden­ti­fy you. This Data Pro­tec­tion Decla­ra­ti­on explains which data we coll­ect as well as the pur­po­ses we use this data for. It also explains how, and for which pur­po­se the infor­ma­ti­on is collected.

We here­wi­th advi­se you that the trans­mis­si­on of data via the Inter­net (i.e., through e‑mail com­mu­ni­ca­ti­ons) may be pro­ne to secu­ri­ty gaps. It is not pos­si­ble to com­ple­te­ly pro­tect data against third-par­ty access.

Information about the responsible party (referred to as the “controller” in the GDPR)

The data pro­ces­sing con­trol­ler on this web­site is:

Swiss Der­ma Cli­nic AG
Löwen­stras­se 1
8001 Zürich
Schweiz

Pho­ne: +41 44 739 9000
E‑mail: info@swissdermaclinic.ch

The con­trol­ler is the natu­ral per­son or legal enti­ty that sin­gle-han­dedly or joint­ly with others makes decis­i­ons as to the pur­po­ses of and resour­ces for the pro­ces­sing of per­so­nal data (e.g., names, e‑mail addres­ses, etc.).

Storage duration

Unless a more spe­ci­fic sto­rage peri­od has been spe­ci­fied in this pri­va­cy poli­cy, your per­so­nal data will remain with us until the pur­po­se for which it was coll­ec­ted no lon­ger appli­es. If you assert a jus­ti­fied request for dele­ti­on or revo­ke your con­sent to data pro­ces­sing, your data will be dele­ted, unless we have other legal­ly per­mis­si­ble reasons for sto­ring your per­so­nal data (e.g., tax or com­mer­cial law reten­ti­on peri­ods); in the lat­ter case, the dele­ti­on will take place after the­se reasons cea­se to apply.

General information on the legal basis for the data processing on this website

If you have con­sen­ted to data pro­ces­sing, we pro­cess your per­so­nal data on the basis of Art. 6(1)(a) GDPR or Art. 9 (2)(a) GDPR, if spe­cial cate­go­ries of data are pro­ces­sed accor­ding to Art. 9 (1) DSGVO. In the case of expli­cit con­sent to the trans­fer of per­so­nal data to third count­ries, the data pro­ces­sing is also based on Art. 49 (1)(a) GDPR. If you have con­sen­ted to the sto­rage of coo­kies or to the access to infor­ma­ti­on in your end device (e.g., via device fin­ger­prin­ting), the data pro­ces­sing is addi­tio­nal­ly based on § 25 (1) TDDDG. The con­sent can be revo­ked at any time. If your data is requi­red for the ful­fill­ment of a con­tract or for the imple­men­ta­ti­on of pre-con­trac­tu­al mea­su­res, we pro­cess your data on the basis of Art. 6(1)(b) GDPR. Fur­ther­mo­re, if your data is requi­red for the ful­fill­ment of a legal obli­ga­ti­on, we pro­cess it on the basis of Art. 6(1)© GDPR. Fur­ther­mo­re, the data pro­ces­sing may be car­ri­ed out on the basis of our legi­ti­ma­te inte­rest accor­ding to Art. 6(1)(f) GDPR. Infor­ma­ti­on on the rele­vant legal basis in each indi­vi­du­al case is pro­vi­ded in the fol­lo­wing para­graphs of this pri­va­cy policy.

Information on the data transfer to third-party countries that are not secure under data protection law and the transfer to US companies that are not DPF-certified

We use, among other tech­no­lo­gies, tools from com­pa­nies loca­ted in third-par­ty count­ries that are not safe under data pro­tec­tion law, as well as US tools who­se pro­vi­ders are not cer­ti­fied under the EU-US Data Pri­va­cy Frame­work (DPF). If the­se tools are enab­led, your per­so­nal data may be trans­fer­red to and pro­ces­sed in the­se count­ries. We would like you to note that no level of data pro­tec­tion com­pa­ra­ble to that in the EU can be gua­ran­teed in third count­ries that are inse­cu­re in terms of data pro­tec­tion law.

We would like to point out that the US, as a secu­re third-par­ty coun­try, gene­ral­ly has a level of data pro­tec­tion com­pa­ra­ble to that of the EU. Data trans­fer to the US is the­r­e­fo­re per­mit­ted if the reci­pi­ent is cer­ti­fied under the “EU-US Data Pri­va­cy Frame­work” (DPF) or has appro­pria­te addi­tio­nal assu­ran­ces. Infor­ma­ti­on on trans­fers to third-par­ty count­ries, inclu­ding the data reci­pi­ents, can be found in this Pri­va­cy Policy.

Recipients of personal data

In the scope of our busi­ness acti­vi­ties, we coope­ra­te with various exter­nal par­ties. In some cases, this also requi­res the trans­fer of per­so­nal data to the­se exter­nal par­ties. We only dis­c­lo­se per­so­nal data to exter­nal par­ties if this is requi­red as part of the ful­fill­ment of a con­tract, if we are legal­ly obli­ga­ted to do so (e.g., dis­clo­sure of data to tax aut­ho­ri­ties), if we have a legi­ti­ma­te inte­rest in the dis­clo­sure pur­su­ant to Art. 6 (1)(f) GDPR, or if ano­ther legal basis per­mits the dis­clo­sure of this data. When using pro­ces­sors, we only dis­c­lo­se per­so­nal data of our cus­to­mers on the basis of a valid con­tract on data pro­ces­sing. In the case of joint pro­ces­sing, a joint pro­ces­sing agree­ment is concluded.

Revocation of your consent to the processing of data

A wide ran­ge of data pro­ces­sing tran­sac­tions are pos­si­ble only sub­ject to your express con­sent. You can also revo­ke at any time any con­sent you have alre­a­dy given us. This shall be wit­hout pre­ju­di­ce to the lawful­ness of any data coll­ec­tion that occur­red pri­or to your revocation.

Right to object to the collection of data in special cases; right to object to direct advertising (Art. 21 GDPR)

IN THE EVENT THAT DATA ARE PROCESSED ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO AT ANY TIME OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA BASED ON GROUNDS ARISING FROM YOUR UNIQUE SITUATION. THIS ALSO APPLIES TO ANY PROFILING BASED ON THESE PROVISIONS. TO DETERMINE THE LEGAL BASIS, ON WHICH ANY PROCESSING OF DATA IS BASED, PLEASE CONSULT THIS DATA PROTECTION DECLARATION. IF YOU LOG AN OBJECTION, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA, UNLESS WE ARE IN A POSITION TO PRESENT COMPELLING PROTECTION WORTHY GROUNDS FOR THE PROCESSING OF YOUR DATA, THAT OUTWEIGH YOUR INTERESTS, RIGHTS AND FREEDOMS OR IF THE PURPOSE OF THE PROCESSING IS THE CLAIMING, EXERCISING OR DEFENCE OF LEGAL ENTITLEMENTS (OBJECTION PURSUANT TO ART. 21(1) GDPR).

IF YOUR PERSONAL DATA IS BEING PROCESSED IN ORDER TO ENGAGE IN DIRECT ADVERTISING, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR AFFECTED PERSONAL DATA FOR THE PURPOSES OF SUCH ADVERTISING AT ANY TIME. THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS AFFILIATED WITH SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT ADVERTISING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).

Right to log a complaint with the competent supervisory agency

In the event of vio­la­ti­ons of the GDPR, data sub­jects are entit­led to log a com­plaint with a super­vi­so­ry agen­cy, in par­ti­cu­lar in the mem­ber sta­te whe­re they usual­ly main­tain their domic­i­le, place of work or at the place whe­re the alle­ged vio­la­ti­on occur­red. The right to log a com­plaint is in effect regard­less of any other admi­nis­tra­ti­ve or court pro­cee­dings available as legal recourses.

Right to data portability

You have the right to have data that we pro­cess auto­ma­ti­cal­ly on the basis of your con­sent or in ful­fill­ment of a con­tract han­ded over to you or to a third par­ty in a com­mon, machi­ne-rea­da­ble for­mat. If you should demand the direct trans­fer of the data to ano­ther con­trol­ler, this will be done only if it is tech­ni­cal­ly feasible.

Information about, rectification and eradication of data

Within the scope of the appli­ca­ble sta­tu­to­ry pro­vi­si­ons, you have the right to demand infor­ma­ti­on about your archi­ved per­so­nal data, their source and reci­pi­ents as well as the pur­po­se of the pro­ces­sing of your data at any time. You may also have a right to have your data rec­ti­fied or era­di­ca­ted. If you have ques­ti­ons about this sub­ject mat­ter or any other ques­ti­ons about per­so­nal data, plea­se do not hesi­ta­te to cont­act us at any time.

Right to demand processing restrictions

You have the right to demand the impo­si­ti­on of rest­ric­tions as far as the pro­ces­sing of your per­so­nal data is con­cer­ned. To do so, you may cont­act us at any time. The right to demand rest­ric­tion of pro­ces­sing appli­es in the fol­lo­wing cases:

  • In the event that you should dis­pu­te the cor­rect­ness of your data archi­ved by us, we will usual­ly need some time to veri­fy this cla­im. During the time that this inves­ti­ga­ti­on is ongo­ing, you have the right to demand that we rest­rict the pro­ces­sing of your per­so­nal data.
  • If the pro­ces­sing of your per­so­nal data was/is con­duc­ted in an unlawful man­ner, you have the opti­on to demand the rest­ric­tion of the pro­ces­sing of your data ins­tead of deman­ding the era­di­ca­ti­on of this data.
  • If we do not need your per­so­nal data any lon­ger and you need it to exer­cise, defend or cla­im legal entit­le­ments, you have the right to demand the rest­ric­tion of the pro­ces­sing of your per­so­nal data ins­tead of its eradication.
  • If you have rai­sed an objec­tion pur­su­ant to Art. 21(1) GDPR, your rights and our rights will have to be weig­hed against each other. As long as it has not been deter­mi­ned who­se inte­rests pre­vail, you have the right to demand a rest­ric­tion of the pro­ces­sing of your per­so­nal data.

If you have rest­ric­ted the pro­ces­sing of your per­so­nal data, the­se data – with the excep­ti­on of their archi­ving – may be pro­ces­sed only sub­ject to your con­sent or to cla­im, exer­cise or defend legal entit­le­ments or to pro­tect the rights of other natu­ral per­sons or legal enti­ties or for important public inte­rest reasons cited by the Euro­pean Uni­on or a mem­ber sta­te of the EU.

SSL and/or TLS encryption

For secu­ri­ty reasons and to pro­tect the trans­mis­si­on of con­fi­den­ti­al con­tent, such as purcha­se orders or inqui­ries you sub­mit to us as the web­site ope­ra­tor, this web­site uses eit­her an SSL or a TLS encryp­ti­on pro­gram. You can reco­gni­ze an encrypt­ed con­nec­tion by che­cking whe­ther the address line of the brow­ser swit­ches from “http://” to “https://” and also by the appearance of the lock icon in the brow­ser line.

If the SSL or TLS encryp­ti­on is acti­va­ted, data you trans­mit to us can­not be read by third parties.

Rejection of unsolicited e‑mails

We here­wi­th object to the use of cont­act infor­ma­ti­on published in con­junc­tion with the man­da­to­ry infor­ma­ti­on to be pro­vi­ded in our Site Noti­ce to send us pro­mo­tio­nal and infor­ma­ti­on mate­ri­al that we have not express­ly reques­ted. The ope­ra­tors of this web­site and its pages reser­ve the express right to take legal action in the event of the unso­li­ci­ted sen­ding of pro­mo­tio­nal infor­ma­ti­on, for ins­tance via SPAM messages.

4. Recording of data on this website

Cookies

Our web­sites and pages use what the indus­try refers to as “coo­kies.” Coo­kies are small data packa­ges that do not cau­se any dama­ge to your device. They are eit­her stored tem­po­r­a­ri­ly for the dura­ti­on of a ses­si­on (ses­si­on coo­kies) or they are per­ma­nent­ly archi­ved on your device (per­ma­nent coo­kies). Ses­si­on coo­kies are auto­ma­ti­cal­ly dele­ted once you ter­mi­na­te your visit. Per­ma­nent coo­kies remain archi­ved on your device until you actively dele­te them, or they are auto­ma­ti­cal­ly era­di­ca­ted by your web browser.

Coo­kies can be issued by us (first-par­ty coo­kies) or by third-par­ty com­pa­nies (so-cal­led third-par­ty coo­kies). Third-par­ty coo­kies enable the inte­gra­ti­on of cer­tain ser­vices of third-par­ty com­pa­nies into web­sites (e.g., coo­kies for hand­ling pay­ment services).

Coo­kies have a varie­ty of func­tions. Many coo­kies are tech­ni­cal­ly essen­ti­al sin­ce cer­tain web­site func­tions would not work in the absence of the­se coo­kies (e.g., the shop­ping cart func­tion or the dis­play of vide­os). Other coo­kies may be used to ana­ly­ze user beha­vi­or or for pro­mo­tio­nal purposes.

Coo­kies, which are requi­red for the per­for­mance of elec­tro­nic com­mu­ni­ca­ti­on tran­sac­tions, for the pro­vi­si­on of cer­tain func­tions you want to use (e.g., for the shop­ping cart func­tion) or tho­se that are neces­sa­ry for the opti­miza­ti­on (requi­red coo­kies) of the web­site (e.g., coo­kies that pro­vi­de mea­sura­ble insights into the web audi­ence), shall be stored on the basis of Art. 6(1)(f) GDPR, unless a dif­fe­rent legal basis is cited. The ope­ra­tor of the web­site has a legi­ti­ma­te inte­rest in the sto­rage of requi­red coo­kies to ensu­re the tech­ni­cal­ly error-free and opti­mi­zed pro­vi­si­on of the operator’s ser­vices. If your con­sent to the sto­rage of the coo­kies and simi­lar reco­gni­ti­on tech­no­lo­gies has been reques­ted, the pro­ces­sing occurs exclu­si­ve­ly on the basis of the con­sent obtai­ned (Art. 6(1)(a) GDPR and § 25 (1) TDDDG); this con­sent may be revo­ked at any time.

You have the opti­on to set up your brow­ser in such a man­ner that you will be noti­fied any time coo­kies are pla­ced and to per­mit the accep­tance of coo­kies only in spe­ci­fic cases. You may also exclude the accep­tance of coo­kies in cer­tain cases or in gene­ral or acti­va­te the dele­te-func­tion for the auto­ma­tic era­di­ca­ti­on of coo­kies when the brow­ser clo­ses. If coo­kies are deac­ti­va­ted, the func­tions of this web­site may be limited.

Which coo­kies and ser­vices are used on this web­site can be found in this pri­va­cy policy.

Consent with Borlabs Cookie

Our web­site uses the Borlabs con­sent tech­no­lo­gy to obtain your con­sent to the sto­rage of cer­tain coo­kies in your brow­ser or for the use of cer­tain tech­no­lo­gies and for their data pri­va­cy pro­tec­tion com­pli­ant docu­men­ta­ti­on. The pro­vi­der of this tech­no­lo­gy is Borlabs GmbH, Rüben­kamp 32, 22305 Ham­burg, Ger­ma­ny (her­ein­af­ter refer­red to as Borlabs).

When­ever you visit our web­site, a Borlabs coo­kie will be stored in your brow­ser, which archi­ves any decla­ra­ti­ons or revo­ca­ti­ons of con­sent you have ente­red. The­se data are not shared with the pro­vi­der of the Borlabs technology.

The recor­ded data shall remain archi­ved until you ask us to era­di­ca­te them, dele­te the Borlabs coo­kie on your own or the pur­po­se of sto­ring the data no lon­ger exists. This shall be wit­hout pre­ju­di­ce to any reten­ti­on obli­ga­ti­ons man­da­ted by law. To review the details of Borlabs’ data pro­ces­sing poli­ci­es, plea­se visit https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/

We use the Borlabs coo­kie con­sent tech­no­lo­gy to obtain the decla­ra­ti­ons of con­sent man­da­ted by law for the use of coo­kies. The legal basis for the use of such coo­kies is Art. 6(1)© GDPR.

Server log files

The pro­vi­der of this web­site and its pages auto­ma­ti­cal­ly coll­ects and stores infor­ma­ti­on in so-cal­led ser­ver log files, which your brow­ser com­mu­ni­ca­tes to us auto­ma­ti­cal­ly. The infor­ma­ti­on comprises:

  • The type and ver­si­on of brow­ser used
  • The used ope­ra­ting system
  • Refer­rer URL
  • The host­na­me of the acces­sing computer
  • The time of the ser­ver inquiry
  • The IP address

This data is not mer­ged with other data sources.

This data is recor­ded on the basis of Art. 6(1)(f) GDPR. The ope­ra­tor of the web­site has a legi­ti­ma­te inte­rest in the tech­ni­cal­ly error free depic­tion and the opti­miza­ti­on of the operator’s web­site. In order to achie­ve this, ser­ver log files must be recorded.

Contact form

If you sub­mit inqui­ries to us via our cont­act form, the infor­ma­ti­on pro­vi­ded in the cont­act form as well as any cont­act infor­ma­ti­on pro­vi­ded the­r­ein will be stored by us in order to hand­le your inquiry and in the event that we have fur­ther ques­ti­ons. We will not share this infor­ma­ti­on wit­hout your consent.

The pro­ces­sing of the­se data is based on Art. 6(1)(b) GDPR, if your request is rela­ted to the exe­cu­ti­on of a con­tract or if it is neces­sa­ry to car­ry out pre-con­trac­tu­al mea­su­res. In all other cases the pro­ces­sing is based on our legi­ti­ma­te inte­rest in the effec­ti­ve pro­ces­sing of the requests addres­sed to us (Art. 6(1)(f) GDPR) or on your agree­ment (Art. 6(1)(a) GDPR) if this has been reques­ted; the con­sent can be revo­ked at any time.

The infor­ma­ti­on you have ente­red into the cont­act form shall remain with us until you ask us to era­di­ca­te the data, revo­ke your con­sent to the archi­ving of data or if the pur­po­se for which the infor­ma­ti­on is being archi­ved no lon­ger exists (e.g., after we have con­cluded our respon­se to your inquiry). This shall be wit­hout pre­ju­di­ce to any man­da­to­ry legal pro­vi­si­ons, in par­ti­cu­lar reten­ti­on periods.

Request by e‑mail, telephone, or fax

If you cont­act us by e‑mail, tele­pho­ne or fax, your request, inclu­ding all resul­ting per­so­nal data (name, request) will be stored and pro­ces­sed by us for the pur­po­se of pro­ces­sing your request. We do not pass the­se data on wit­hout your consent.

The­se data are pro­ces­sed on the basis of Art. 6(1)(b) GDPR if your inquiry is rela­ted to the ful­fill­ment of a con­tract or is requi­red for the per­for­mance of pre-con­trac­tu­al mea­su­res. In all other cases, the data are pro­ces­sed on the basis of our legi­ti­ma­te inte­rest in the effec­ti­ve hand­ling of inqui­ries sub­mit­ted to us (Art. 6(1)(f) GDPR) or on the basis of your con­sent (Art. 6(1)(a) GDPR) if it has been obtai­ned; the con­sent can be revo­ked at any time.

The data sent by you to us via cont­act requests remain with us until you request us to dele­te, revo­ke your con­sent to the sto­rage or the pur­po­se for the data sto­rage lap­ses (e.g. after com­ple­ti­on of your request). Man­da­to­ry sta­tu­to­ry pro­vi­si­ons – in par­ti­cu­lar sta­tu­to­ry reten­ti­on peri­ods – remain unaffected.

Communication via WhatsApp

For com­mu­ni­ca­ti­on with our cus­to­mers and other third par­ties, one of the ser­vices we use is the instant mes­sa­ging ser­vice Whats­App. The pro­vi­der is Whats­App Ire­land Limi­t­ed, 4 Grand Canal Squa­re, Grand Canal Har­bour, Dub­lin 2, Ireland.

The com­mu­ni­ca­ti­on is encrypt­ed end-to-end (peer-to-peer), which pre­vents Whats­App or other third par­ties from gai­ning access to the com­mu­ni­ca­ti­on con­tent. Howe­ver, Whats­App does gain access to meta­da­ta crea­ted during the com­mu­ni­ca­ti­on pro­cess (for exam­p­le, sen­der, reci­pi­ent, and time). We would also like to point out that Whats­App has sta­ted that it shares per­so­nal data of its users with its U.S.-based parent com­pa­ny Meta. Fur­ther details on data pro­ces­sing can be found in the Whats­App pri­va­cy poli­cy at: https://www.whatsapp.com/legal/#privacy-policy.

The use of Whats­App is based on our legi­ti­ma­te inte­rest in com­mu­ni­ca­ting as quick­ly and effec­tively as pos­si­ble with cus­to­mers, inte­res­ted par­ties and other busi­ness and con­trac­tu­al part­ners (Art. 6(1)(f) GDPR). If a cor­re­spon­ding con­sent has been reques­ted, data pro­ces­sing is car­ri­ed out exclu­si­ve­ly on the basis of the con­sent; this con­sent may be revo­ked at any time with effect for the future.

The com­mu­ni­ca­ti­on con­tent exch­an­ged bet­ween you and us on Whats­App remains with us until you request us to dele­te it, revo­ke your con­sent to sto­rage or the pur­po­se for which the data is stored cea­ses to app­ly (e.g. after your request has been pro­ces­sed). Man­da­to­ry legal pro­vi­si­ons, in par­ti­cu­lar reten­ti­on peri­ods, remain unaffected.

The com­pa­ny is cer­ti­fied in accordance with the “EU-US Data Pri­va­cy Frame­work” (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the US, which is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every com­pa­ny cer­ti­fied under the DPF is obli­ged to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/7735.

We use Whats­App in the “Whats­App Busi­ness” variant.

Data trans­mis­si­on to the US is based on the Stan­dard Con­trac­tu­al Clau­ses (SCC) of the Euro­pean Com­mis­si­on. Details can be found here: https://www.whatsapp.com/legal/business-data-transfer-addendum?lang=en.

We have con­cluded a data pro­ces­sing agree­ment (DPA) with the abo­ve-men­tio­ned provider.

5. Social media

Instagram

We have inte­gra­ted func­tions of the public media plat­form Insta­gram into this web­site. The­se func­tions are being offe­red by Meta Plat­forms Ire­land Limi­t­ed, Mer­ri­on Road, Dub­lin 4, D04 X2K5, Ireland.

If the social media ele­ment has been acti­va­ted, a direct con­nec­tion bet­ween your device and Instagram’s ser­ver will be estab­lished. As a result, Insta­gram will recei­ve infor­ma­ti­on on your visit to this website.

If you are log­ged into your Insta­gram account, you may click the Insta­gram but­ton to link con­tents from this web­site to your Insta­gram pro­fi­le. This enables Insta­gram to allo­ca­te your visit to this web­site to your user account. We have to point out that we as the pro­vi­der of the web­site and its pages do not have any know­ledge of the con­tent of the data trans­fer­red and its use by Instagram.

The use of this ser­vice is based on your con­sent in accordance with Art. 6 (1)(a) GDPR and § 25 (1) TDDDG. Con­sent can be revo­ked at any time.

Inso­far as per­so­nal data is coll­ec­ted on our web­site with the help of the tool descri­bed here and for­ward­ed to Face­book or Insta­gram, we and Meta Plat­forms Ire­land Limi­t­ed, 4 Grand Canal Squa­re, Grand Canal Har­bour, Dub­lin 2, Ire­land are joint­ly respon­si­ble for this data pro­ces­sing (Art. 26 DSGVO). The joint respon­si­bi­li­ty is limi­t­ed exclu­si­ve­ly to the coll­ec­tion of the data and its for­war­ding to Face­book or Insta­gram. The pro­ces­sing by Face­book or Insta­gram that takes place after the onward trans­fer is not part of the joint respon­si­bi­li­ty. The obli­ga­ti­ons incum­bent on us joint­ly have been set out in a joint pro­ces­sing agree­ment. The wor­ding of the agree­ment can be found under: https://www.facebook.com/legal/controller_addendum. Accor­ding to this agree­ment, we are respon­si­ble for pro­vi­ding the pri­va­cy infor­ma­ti­on when using the Face­book or Insta­gram tool and for the pri­va­cy-secu­re imple­men­ta­ti­on of the tool on our web­site. Face­book is respon­si­ble for the data secu­ri­ty of Face­book or Insta­gram pro­ducts. You can assert data sub­ject rights (e.g., requests for infor­ma­ti­on) regar­ding data pro­ces­sed by Face­book or Insta­gram direct­ly with Face­book. If you assert the data sub­ject rights with us, we are obli­ged to for­ward them to Facebook.

Data trans­mis­si­on to the US is based on the Stan­dard Con­trac­tu­al Clau­ses (SCC) of the Euro­pean Com­mis­si­on. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://privacycenter.instagram.com/policy/ and https://de-de.facebook.com/help/566994660333381.

For more infor­ma­ti­on on this sub­ject, plea­se con­sult Instagram’s Data Pri­va­cy Decla­ra­ti­on at: https://privacycenter.instagram.com/policy/.

The com­pa­ny is cer­ti­fied in accordance with the “EU-US Data Pri­va­cy Frame­work” (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the US, which is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every com­pa­ny cer­ti­fied under the DPF is obli­ged to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/4452.

6. Analysis tools and advertising

Google Tag Manager

We use the Goog­le Tag Mana­ger. The pro­vi­der is Goog­le Ire­land Limi­t­ed, Gor­don House, Bar­row Street, Dub­lin 4, Ireland

The Goog­le Tag Mana­ger is a tool that allows us to inte­gra­te track­ing or sta­tis­ti­cal tools and other tech­no­lo­gies on our web­site. The Goog­le Tag Mana­ger its­elf does not crea­te any user pro­files, does not store coo­kies, and does not car­ry out any inde­pen­dent ana­ly­ses. It only mana­ges and runs the tools inte­gra­ted via it. Howe­ver, the Goog­le Tag Mana­ger does coll­ect your IP address, which may also be trans­fer­red to Google’s parent com­pa­ny in the United States.

The Goog­le Tag Mana­ger is used on the basis of Art. 6(1)(f) GDPR. The web­site ope­ra­tor has a legi­ti­ma­te inte­rest in the quick and uncom­pli­ca­ted inte­gra­ti­on and admi­nis­tra­ti­on of various tools on his web­site. If appro­pria­te con­sent has been obtai­ned, the pro­ces­sing is car­ri­ed out exclu­si­ve­ly on the basis of Art. 6(1)(a) GDPR and § 25 (1) TDDDG, inso­far the con­sent includes the sto­rage of coo­kies or the access to infor­ma­ti­on in the user’s end device (e.g., device fin­ger­prin­ting) within the mea­ning of the TDDDG. This con­sent can be revo­ked at any time.

The com­pa­ny is cer­ti­fied in accordance with the “EU-US Data Pri­va­cy Frame­work” (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the US, which is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every com­pa­ny cer­ti­fied under the DPF is obli­ged to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

Google Analytics

This web­site uses func­tions of the web ana­ly­sis ser­vice Goog­le Ana­ly­tics. The pro­vi­der of this ser­vice is Goog­le Ire­land Limi­t­ed (“Goog­le”), Gor­don House, Bar­row Street, Dub­lin 4, Ireland.

Goog­le Ana­ly­tics enables the web­site ope­ra­tor to ana­ly­ze the beha­vi­or pat­terns of web­site visi­tors. To that end, the web­site ope­ra­tor recei­ves a varie­ty of user data, such as pages acces­sed, time spent on the page, the uti­li­zed ope­ra­ting sys­tem and the user’s ori­gin. This data is sum­ma­ri­zed in a user-ID and assi­gned to the respec­ti­ve end device of the web­site visitor.

Fur­ther­mo­re, Goog­le Ana­ly­tics allows us to record your mou­se and scroll move­ments and clicks, among other things. Goog­le Ana­ly­tics uses various mode­ling approa­ches to aug­ment the coll­ec­ted data sets and uses machi­ne lear­ning tech­no­lo­gies in data analysis.

Goog­le Ana­ly­tics uses tech­no­lo­gies that make the reco­gni­ti­on of the user for the pur­po­se of ana­ly­zing the user beha­vi­or pat­terns (e.g., coo­kies or device fin­ger­prin­ting). The web­site use infor­ma­ti­on recor­ded by Goog­le is, as a rule trans­fer­red to a Goog­le ser­ver in the United Sta­tes, whe­re it is stored.

The use of the­se ser­vices occurs on the basis of your con­sent pur­su­ant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may revo­ke your con­sent at any time.

Data trans­mis­si­on to the US is based on the Stan­dard Con­trac­tu­al Clau­ses (SCC) of the Euro­pean Com­mis­si­on. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/.

The com­pa­ny is cer­ti­fied in accordance with the “EU-US Data Pri­va­cy Frame­work” (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the US, which is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every com­pa­ny cer­ti­fied under the DPF is obli­ged to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

IP anonymization

Goog­le Ana­ly­tics IP anony­miza­ti­on is acti­ve. As a result, your IP address will be abbre­via­ted by Goog­le within the mem­ber sta­tes of the Euro­pean Uni­on or in other sta­tes that have rati­fied the Con­ven­ti­on on the Euro­pean Eco­no­mic Area pri­or to its trans­mis­si­on to the United Sta­tes. The full IP address will be trans­mit­ted to one of Google’s ser­vers in the United Sta­tes and abbre­via­ted the­re only in excep­tio­nal cases. On behalf of the ope­ra­tor of this web­site, Goog­le shall use this infor­ma­ti­on to ana­ly­ze your use of this web­site to gene­ra­te reports on web­site acti­vi­ties and to ren­der other ser­vices to the ope­ra­tor of this web­site that are rela­ted to the use of the web­site and the Inter­net. The IP address trans­mit­ted in con­junc­tion with Goog­le Ana­ly­tics from your brow­ser shall not be mer­ged with other data in Google’s possession.

Browser plug-in

You can pre­vent the recor­ding and pro­ces­sing of your data by Goog­le by down­loa­ding and instal­ling the brow­ser plug­in available under the fol­lo­wing link: https://tools.google.com/dlpage/gaoptout?hl=en.

For more infor­ma­ti­on about the hand­ling of user data by Goog­le Ana­ly­tics, plea­se con­sult Google’s Data Pri­va­cy Decla­ra­ti­on at: https://support.google.com/analytics/answer/6004245?hl=en.

Contract data processing

We have exe­cu­ted a con­tract data pro­ces­sing agree­ment with Goog­le and are imple­men­ting the strin­gent pro­vi­si­ons of the Ger­man data pro­tec­tion agen­ci­es to the ful­lest when using Goog­le Analytics.

Google Ads

The web­site ope­ra­tor uses Goog­le Ads. Goog­le Ads is an online pro­mo­tio­nal pro­gram of Goog­le Ire­land Limi­t­ed (“Goog­le”), Gor­don House, Bar­row Street, Dub­lin 4, Ireland.

Goog­le Ads enables us to dis­play ads in the Goog­le search engi­ne or on third-par­ty web­sites, if the user enters cer­tain search terms into Goog­le (key­word tar­ge­ting). It is also pos­si­ble to place tar­ge­ted ads based on the user data Goog­le has in its pos­ses­si­on (e.g., loca­ti­on data and inte­rests; tar­get group tar­ge­ting). As the web­site ope­ra­tor, we can ana­ly­ze the­se data quan­ti­ta­tively, for ins­tance by ana­ly­zing which search terms resul­ted in the dis­play of our ads and how many ads led to respec­ti­ve clicks.

The use of the­se ser­vices occurs on the basis of your con­sent pur­su­ant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may revo­ke your con­sent at any time.

Data trans­mis­si­on to the US is based on the Stan­dard Con­trac­tu­al Clau­ses (SCC) of the Euro­pean Com­mis­si­on. Details can be found here: https://policies.google.com/privacy/frameworks and https://business.safety.google/controllerterms/.

The com­pa­ny is cer­ti­fied in accordance with the “EU-US Data Pri­va­cy Frame­work” (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the US, which is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every com­pa­ny cer­ti­fied under the DPF is obli­ged to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

Google Conversion-Tracking

This web­site uses Goog­le Con­ver­si­on Track­ing. The pro­vi­der of this ser­vice is Goog­le Ire­land Limi­t­ed (“Goog­le”), Gor­don House, Bar­row Street, Dub­lin 4, Ireland.

With the assis­tance of Goog­le Con­ver­si­on Track­ing, we are in a posi­ti­on to reco­gni­ze whe­ther the user has com­ple­ted cer­tain actions. For ins­tance, we can ana­ly­ze the how fre­quent­ly which but­tons on our web­site have been cli­cked and which pro­ducts are review­ed or purcha­sed with par­ti­cu­lar fre­quen­cy. The pur­po­se of this infor­ma­ti­on is to com­pi­le con­ver­si­on sta­tis­tics. We learn how many users have cli­cked on our ads and which actions they have com­ple­ted. We do not recei­ve any infor­ma­ti­on that would allow us to per­so­nal­ly iden­ti­fy the users. Goog­le as such uses coo­kies or com­pa­ra­ble reco­gni­ti­on tech­no­lo­gies for iden­ti­fi­ca­ti­on purposes.

The use of the­se ser­vices occurs on the basis of your con­sent pur­su­ant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may revo­ke your con­sent at any time.

For more infor­ma­ti­on about Goog­le Con­ver­si­on Track­ing, plea­se review Google’s data pro­tec­tion poli­cy at: https://policies.google.com/privacy?hl=en

The com­pa­ny is cer­ti­fied in accordance with the “EU-US Data Pri­va­cy Frame­work” (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the US, which is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every com­pa­ny cer­ti­fied under the DPF is obli­ged to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

Meta Pixel (formerly Facebook Pixel)

To mea­su­re con­ver­si­on rates, this web­site uses the visi­tor acti­vi­ty pixel of Meta. The pro­vi­der of this ser­vice is Meta Plat­forms Ire­land Limi­t­ed, 4 Grand Canal Squa­re, Dub­lin 2, Ire­land. Accor­ding to Meta’s state­ment the coll­ec­ted data will be trans­fer­red to the USA and other third-par­ty count­ries too.

This tool allows the track­ing of page visi­tors after they have been lin­ked to the web­site of the pro­vi­der after cli­cking on a Meta ad. This makes it pos­si­ble to ana­ly­ze the effec­ti­ve­ness of Meta ads for sta­tis­ti­cal and mar­ket rese­arch pur­po­ses and to opti­mi­ze future adver­ti­sing campaigns.

For us as the ope­ra­tors of this web­site, the coll­ec­ted data is anony­mous. We are not in a posi­ti­on to arri­ve at any con­clu­si­ons as to the iden­ti­ty of users. Howe­ver, Meta archi­ves the infor­ma­ti­on and pro­ces­ses it, so that it is pos­si­ble to make a con­nec­tion to the respec­ti­ve user pro­fi­le on Face­book or Insta­gram and Meta is in a posi­ti­on to use the data for its own pro­mo­tio­nal pur­po­ses in com­pli­ance with the Meta Data Usa­ge Poli­cy (https://www.facebook.com/about/privacy/). This enables Meta to dis­play ads on Face­book or Insta­gram and other adver­ti­sing chan­nels. We as the ope­ra­tor of this web­site have no con­trol over the use of such data.

The use of the­se ser­vices occurs on the basis of your con­sent pur­su­ant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may revo­ke your con­sent at any time.

Within the meta pixel, we are using the expan­ded ali­gnment function.

The expan­ded ali­gnment allows us to trans­fer to Meta dif­fe­rent types of data (e.g., place of resi­dence, fede­ral sta­te, zip code, hash­ed email addres­ses, names, gen­der, date of birth or pho­ne num­ber) of our cus­to­mers and pro­s­pects we coll­ect through our web­site. Here­wi­th, we can tail­or the offers pre­sen­ted in our adver­ti­sing cam­paigns on Face­book and Insta­gram to indi­vi­du­als inte­res­ted in what we offer even more pre­cis­e­ly. Moreo­ver, this expan­ded ali­gnment opti­mi­zes the allo­ca­ti­on of web­site con­ver­si­ons and expands cus­tom audiences.

Inso­far as per­so­nal data is coll­ec­ted on our web­site with the help of the tool descri­bed here and for­ward­ed to Meta, we and Meta Plat­forms Ire­land Limi­t­ed, 4 Grand Canal Squa­re, Grand Canal Har­bour, Dub­lin 2, Ire­land are joint­ly respon­si­ble for this data pro­ces­sing (Art. 26 DSGVO). The joint respon­si­bi­li­ty is limi­t­ed exclu­si­ve­ly to the coll­ec­tion of the data and its for­war­ding to Meta. The pro­ces­sing by Meta that takes place after the onward trans­fer is not part of the joint respon­si­bi­li­ty. The obli­ga­ti­ons incum­bent on us have been joint­ly set out in a joint pro­ces­sing agree­ment. The wor­ding of the agree­ment can be found under: https://www.facebook.com/legal/controller_addendum. Accor­ding to this agree­ment, we are respon­si­ble for pro­vi­ding the pri­va­cy infor­ma­ti­on when using the Meta tool and for the pri­va­cy-secu­re imple­men­ta­ti­on of the tool on our web­site. Meta is respon­si­ble for the data secu­ri­ty of Meta pro­ducts. You can assert data sub­ject rights (e.g., requests for infor­ma­ti­on) regar­ding data pro­ces­sed by Face­book or Insta­gram direct­ly with Meta. If you assert the data sub­ject rights with us, we are obli­ged to for­ward them to Meta.

Data trans­mis­si­on to the US is based on the Stan­dard Con­trac­tu­al Clau­ses (SCC) of the Euro­pean Com­mis­si­on. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

In Meta’s Data Pri­va­cy Poli­ci­es, you will find addi­tio­nal infor­ma­ti­on about the pro­tec­tion of your pri­va­cy at: https://www.facebook.com/about/privacy/.

You also have the opti­on to deac­ti­va­te the remar­ke­ting func­tion “Cus­tom Audi­en­ces” in the ad set­tings sec­tion under https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. To do this, you first have to log into Facebook.

If you do not have a Face­book or Insta­gram account, you can deac­ti­va­te any user-based adver­ti­sing by Meta on the web­site of the Euro­pean Inter­ac­ti­ve Digi­tal Adver­ti­sing Alli­ance: http://www.youronlinechoices.com/de/praferenzmanagement/.

The com­pa­ny is cer­ti­fied in accordance with the “EU-US Data Pri­va­cy Frame­work” (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the US, which is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every com­pa­ny cer­ti­fied under the DPF is obli­ged to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/4452.

Meta Conversion API

We have inte­gra­ted the Meta Con­ver­si­on API into this web­site. The pro­vi­der of this ser­vice is Meta Plat­forms Ire­land Limi­t­ed, 4 Grand Canal Squa­re, Dub­lin 2, Ire­land. Howe­ver, based on the infor­ma­ti­on pro­vi­ded by Meta, the recor­ded data is also trans­mit­ted to the United Sta­tes and other Non-EU and Non-EEZ countries.

Meta Con­ver­si­on API enables us to record the inter­ac­tions of our web­site visi­tors with our web­site and to share this infor­ma­ti­on with Meta to impro­ve the pro­mo­tio­nal per­for­mance with Face­book and Instagram.

To do this, in par­ti­cu­lar the time you acces­sed the site, the web­site you acces­sed, your IP address and your user agent, as well as, if appli­ca­ble, other spe­ci­fic data (e.g., purcha­sed pro­ducts, value of the shop­ping cart and cur­ren­cy) are tra­cked. For a com­ple­te over­view of the tra­cked data, plea­se visit: https://developers.facebook.com/docs/marketing-api/conversions-api/parameters.

The use of this ser­vice occurs on the basis of your con­sent pur­su­ant to Art. 6 Sect. 1 lit. a GDPR and § 25 Sect. 1 TDDDG. You may revo­ke your con­sent at any time.

If per­so­nal data is coll­ec­ted on our web­site with the assis­tance of the tool descri­bed her­ein and if it is shared with Meta, we and Meta Plat­forms Ire­land Limi­t­ed, 4 Grand Canal Squa­re, Grand Canal Har­bour, Dub­lin 2, Ire­land shall be joint­ly respon­si­ble for the pro­ces­sing of your data, i.e., we are the data con­trol­lers (Art. 26 GDPR). This shared respon­si­bi­li­ty is limi­t­ed exclu­si­ve­ly to the recor­ding of your data and its sha­ring with Meta. The pro­ces­sing that occurs after the data has been shared with Meta is not part of this shared respon­si­bi­li­ty. The obli­ga­ti­ons we share respon­si­bi­li­ty for have been docu­men­ted in an agree­ment on joint pro­ces­sing. The con­cre­te wor­ding of this agree­ment can be found at: https://www.facebook.com/legal/controller_addendum. Accor­ding to this agree­ment, we are respon­si­ble for the pro­vi­si­on of the data pro­tec­tion infor­ma­ti­on when using the Meta tool and for the data pro­tec­tion law com­pli­ant secu­re imple­men­ta­ti­on of the tool on our web­site. Meta is lia­ble for the data secu­ri­ty of Meta pro­ducts. You may request infor­ma­ti­on on your rights as a data sub­ject (e.g., request for infor­ma­ti­on) rela­ted to the data pro­ces­sed by Face­book or Insta­gram direct­ly from Meta. If you cla­im any data sub­ject rights with us, we are requi­red to for­ward your request to Meta.

The trans­fer of data to the United Sta­tes is based on the stan­dard con­tract clau­ses of the EU com­mis­si­on. For details plea­se visit: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

In Meta’s data pri­va­cy poli­cy, you will find addi­tio­nal infor­ma­ti­on per­tai­ning to the pro­tec­tion of your pri­va­cy: https://de-de.facebook.com/about/privacy/.

You can also deac­ti­va­te the remar­ke­ting func­tion ‘Cus­tom Audi­en­ces’ in the set­tings for adverts at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. To do this, you must be log­ged in to Facebook.

If you do not have a Face­book account with Face­book or Insta­gram, you can deac­ti­va­te usa­ge-based adver­ti­sing from Meta on the web­site of the Euro­pean Inter­ac­ti­ve Digi­tal Adver­ti­sing Alli­ance: http://www.youronlinechoices.com/de/praferenzmanagement/.

The com­pa­ny is cer­ti­fied in accordance with the “EU-US Data Pri­va­cy Frame­work” (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the US, which is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every com­pa­ny cer­ti­fied under the DPF is obli­ged to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/4452.

Data processing

We have con­cluded a data pro­ces­sing agree­ment (DPA) for the use of the abo­ve-men­tio­ned ser­vice. This is a con­tract man­da­ted by data pri­va­cy laws that gua­ran­tees that they pro­cess per­so­nal data of our web­site visi­tors only based on our ins­truc­tions and in com­pli­ance with the GDPR.

Meta Custom Audiences

We use Meta Cus­tom Audi­en­ces. The pro­vi­der of this ser­vice is Meta Plat­forms Ire­land Limi­t­ed, 4 Grand Canal Squa­re, Dub­lin 2, Ireland.

When­ever you visit or use our web­site and apps, uti­li­ze our port­fo­lio (e.g., par­ti­ci­pa­ti­on in sweepsta­kes), trans­fer data to us or inter­act with the Face­book or Insta­gram con­tent of our com­pa­ny, we record rela­ted per­so­nal data. In the event that you have given us your con­sent to the use of Meta Cus­tom Audi­en­ces, we will share the­se data with Meta to put Meta in a posi­ti­on to send you com­pa­ti­ble ads. The­se data may also be used to defi­ned tar­get audi­en­ces (Loo­ka­li­ke Audiences).

Meta pro­ces­ses the­se data as our con­tract pro­ces­sor. For details, plea­se con­sult the user agree­ment of Meta: https://www.facebook.com/legal/terms/customaudience.

The use of the­se ser­vices occurs on the basis of your con­sent pur­su­ant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may revo­ke your con­sent at any time.

The trans­fer of date to the USA is based on the stan­dard con­tract clau­ses of the EU Com­mis­si­on. For details plea­se see: https://www.facebook.com/legal/terms/customaudience and https://www.facebook.com/legal/terms/dataprocessing.

The com­pa­ny is cer­ti­fied in accordance with the “EU-US Data Pri­va­cy Frame­work” (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the US, which is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every com­pa­ny cer­ti­fied under the DPF is obli­ged to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/4452.

7. Newsletter

Newsletter data

If you would like to recei­ve the news­let­ter offe­red on the web­site, we requi­re an e‑mail address from you as well as infor­ma­ti­on that allows us to veri­fy that you are the owner of the e‑mail address pro­vi­ded and that you agree to recei­ve the news­let­ter. Fur­ther data is not coll­ec­ted or only on a vol­un­t­a­ry basis. For the hand­ling of the news­let­ter, we use news­let­ter ser­vice pro­vi­ders, which are descri­bed below.

MailerLite

This web­site uses Mail­er­Li­te to send news­let­ters. The pro­vi­der is Mail­er­Li­te Limi­t­ed, “Mail­er­Li­te”, 38 Mount Street Upper, Dub­lin 2, D02PR89 Ire­land (her­ein­af­ter „Mail­er­Li­te“).

Mail­er­Li­te is a ser­vice that, among other things, can be used to orga­ni­ze and ana­ly­ze the sen­ding of news­let­ters. The data you enter to sub­scri­be to the news­let­ter is stored on MailerLite’s servers.

If you do not want Mail­er­Li­te to ana­ly­ze your data, you must unsub­scri­be from the news­let­ter. For this pur­po­se, we pro­vi­de a cor­re­spon­ding link in every news­let­ter message.

Data analysis by MailerLite

Mail­er­Li­te enables us to ana­ly­ze our news­let­ter cam­paigns. For exam­p­le, we can see whe­ther a news­let­ter mes­sa­ge was ope­ned, and which links were cli­cked on, if any. In this way we can deter­mi­ne which links were cli­cked on par­ti­cu­lar­ly often.

We can also see whe­ther cer­tain pre­vious­ly defi­ned actions were car­ri­ed out after opening/clicking (con­ver­si­on rate). For exam­p­le, we can see whe­ther you have made a purcha­se after cli­cking on the newsletter.

Mail­er­Li­te also enables us to divi­de the news­let­ter reci­pi­ents into dif­fe­rent cate­go­ries (“clus­te­ring”). The news­let­ter reci­pi­ents can be divi­ded accor­ding to age, gen­der, or place of resi­dence, for exam­p­le. In this way, the news­let­ters can be bet­ter adapt­ed to the respec­ti­ve tar­get groups.

Detail­ed infor­ma­ti­on on the func­tions of Mail­er­Li­te can be found at the fol­lo­wing link: https://www.mailerlite.com/features.

The Mail­er­Li­te pri­va­cy poli­cy can be found at: https://www.mailerlite.com/legal/privacy-policy.

Legal basis

Data pro­ces­sing is based on your con­sent (Art. 6(1)(a) GDPR). You can revo­ke this con­sent at any time for the future.

Storage period

The data you pro­vi­de us with for the pur­po­se of sub­scrib­ing to the news­let­ter will be stored by us or the news­let­ter ser­vice pro­vi­der until you unsub­scri­be from the news­let­ter and dele­ted from the news­let­ter dis­tri­bu­ti­on list after you unsub­scri­be from the news­let­ter or after the pur­po­se has cea­sed to app­ly. We reser­ve the right to dele­te or block e‑mail addres­ses from our news­let­ter dis­tri­bu­ti­on list at our own dis­cre­ti­on within the scope of our legi­ti­ma­te inte­rest in accordance with Art. 6(1)(f) GDPR. This does not affect data stored by us for other purposes.

After you have been remo­ved from the news­let­ter dis­tri­bu­ti­on list, your e‑mail address may be stored by us or the news­let­ter ser­vice pro­vi­der in a black­list, if such action is neces­sa­ry to pre­vent future mai­lings. The data from the black­list will only be used for this pur­po­se and will not be mer­ged with other data. This ser­ves both your inte­rest and our inte­rest in com­pli­ance with the legal requi­re­ments when sen­ding news­let­ters (legi­ti­ma­te inte­rest in the sen­se of Art. 6(1)(f) GDPR). The­re is no time limit on sto­rage in the black­list. You can object to the sto­rage if your inte­rests out­weigh our legi­ti­ma­te interest.

Data processing

We have con­cluded a data pro­ces­sing agree­ment (DPA) for the use of the abo­ve-men­tio­ned ser­vice. This is a con­tract man­da­ted by data pri­va­cy laws that gua­ran­tees that they pro­cess per­so­nal data of our web­site visi­tors only based on our ins­truc­tions and in com­pli­ance with the GDPR.

8. Plug-ins and Tools

YouTube with expanded data protection integration

This web­site inte­gra­tes vide­os from the You­Tube web­site. The ope­ra­tor of the web­site is Goog­le Ire­land Limi­t­ed (“Goog­le”), Gor­don House, Bar­row Street, Dub­lin 4, Ireland.

When you visit one of the­se web­sites on which You­Tube is inte­gra­ted, a con­nec­tion to the You­Tube ser­vers is estab­lished. This tells the You­Tube ser­ver which of our pages you have visi­ted. If you are log­ged into your You­Tube account, you enable You­Tube to assign your sur­fing beha­vi­or direct­ly to your per­so­nal pro­fi­le. You can pre­vent this by log­ging out of your You­Tube account.

We use You­Tube in exten­ded data pro­tec­tion mode. Accor­ding to You­Tube, vide­os that are play­ed in exten­ded data pro­tec­tion mode are not used to per­so­na­li­ze brow­sing on You­Tube. Ads that are play­ed in exten­ded data pro­tec­tion mode are also not per­so­na­li­zed. No coo­kies are set in exten­ded data pro­tec­tion mode. Ins­tead, so-cal­led local sto­rage ele­ments are stored in the user’s brow­ser, which con­tain per­so­nal data simi­lar to coo­kies and can be used for reco­gni­ti­on. Details on the exten­ded data pro­tec­tion mode can be found here: https://support.google.com/youtube/answer/171780.

After acti­vat­ing a You­Tube video, fur­ther data pro­ces­sing ope­ra­ti­ons may be trig­ge­red over which we have no influence.

The use of You­Tube is based on our inte­rest in pre­sen­ting our online con­tent in an appe­al­ing man­ner. Pur­su­ant to Art. 6(1)(f) GDPR, this is a legi­ti­ma­te inte­rest. If appro­pria­te con­sent has been obtai­ned, the pro­ces­sing is car­ri­ed out exclu­si­ve­ly on the basis of Art. 6(1)(a) GDPR and § 25 (1) TDDDG, inso­far the con­sent includes the sto­rage of coo­kies or the access to infor­ma­ti­on in the user’s end device (e.g., device fin­ger­prin­ting) within the mea­ning of the TDDDG. This con­sent can be revo­ked at any time.

For more infor­ma­ti­on on how You­Tube hand­les user data, plea­se con­sult the You­Tube Data Pri­va­cy Poli­cy under: https://policies.google.com/privacy?hl=en.

The com­pa­ny is cer­ti­fied in accordance with the “EU-US Data Pri­va­cy Frame­work” (DPF). The DPF is an agree­ment bet­ween the Euro­pean Uni­on and the US, which is inten­ded to ensu­re com­pli­ance with Euro­pean data pro­tec­tion stan­dards for data pro­ces­sing in the US. Every com­pa­ny cer­ti­fied under the DPF is obli­ged to com­ply with the­se data pro­tec­tion stan­dards. For more infor­ma­ti­on, plea­se cont­act the pro­vi­der under the fol­lo­wing link: https://www.dataprivacyframework.gov/participant/5780.

Google Fonts (local embedding)

This web­site uses so-cal­led Goog­le Fonts pro­vi­ded by Goog­le to ensu­re the uni­form use of fonts on this site. The­se Goog­le fonts are local­ly instal­led so that a con­nec­tion to Google’s ser­vers will not be estab­lished in con­junc­tion with this application.

For more infor­ma­ti­on on Goog­le Fonts, plea­se fol­low this link: https://developers.google.com/fonts/faq and con­sult Google’s Data Pri­va­cy Decla­ra­ti­on under: https://policies.google.com/privacy?hl=en.

Font Awesome

This page uses Font Awe­so­me for the uni­form repre­sen­ta­ti­on of fonts and sym­bols. Pro­vi­der is Fon­ti­cons, Inc. 6 Por­ter Road Apart­ment 3R, Cam­bridge, Mas­sa­chu­setts, USA.

When you call up a page, your brow­ser loads the requi­red fonts into its brow­ser cache to dis­play texts, fonts, and sym­bols cor­rect­ly. For this pur­po­se, the brow­ser you use must con­nect to the ser­vers of Font Awe­so­me. This allows Font Awe­so­me to know that your IP address has been used to access this web­site. The use of Font Awe­so­me is based on Art. 6(1)(f) GDPR. We have a legi­ti­ma­te inte­rest in the uni­form pre­sen­ta­ti­on of the type­face on our web­site. If appro­pria­te con­sent has been obtai­ned, the pro­ces­sing is car­ri­ed out exclu­si­ve­ly on the basis of Art. 6(1)(a) GDPR and § 25 (1) TDDDG, inso­far the con­sent includes the sto­rage of coo­kies or the access to infor­ma­ti­on in the user’s end device (e.g., device fin­ger­prin­ting) within the mea­ning of the TDDDG. This con­sent can be revo­ked at any time.

If your brow­ser does not sup­port Font Awe­so­me, a stan­dard font from your com­pu­ter will be used.

Fur­ther infor­ma­ti­on about Font Awe­so­me can be found in the Font Awe­so­me pri­va­cy poli­cy at: https://fontawesome.com/privacy.

Wordfence

We have included Word­fence on this web­site. The pro­vi­der is Defi­ant Inc, Defi­ant, Inc, 800 5th Ave Ste 4100, Seat­tle, WA 98104, USA (her­ein­af­ter “Word­fence”).

Word­fence is desi­gned to pro­tect our web­site from unwan­ted access or mali­cious cyber­at­tacks. To accom­plish this, our web­site estab­lishes a per­ma­nent con­nec­tion with Wordfence’s ser­vers, which check and block their data­ba­ses against access to our website.

The use of Word­fence is based on Art. 6(1)(f) GDPR. The web­site ope­ra­tor has a legi­ti­ma­te inte­rest in the most effec­ti­ve pro­tec­tion of his web­site against cyber­at­tacks. If appro­pria­te con­sent has been obtai­ned, the pro­ces­sing is car­ri­ed out exclu­si­ve­ly on the basis of Art. 6(1)(a) GDPR and § 25 (1) TDDDG, inso­far the con­sent includes the sto­rage of coo­kies or the access to infor­ma­ti­on in the user’s end device (e.g., device fin­ger­prin­ting) within the mea­ning of the TDDDG. This con­sent can be revo­ked at any time.

Data trans­mis­si­on to the USA is based on the stan­dard con­trac­tu­al clau­ses of the EU Com­mis­si­on. Details can be found here: https://www.wordfence.com/help/general-data-protection-regulation/.

Data processing

We have con­cluded a data pro­ces­sing agree­ment (DPA) for the use of the abo­ve-men­tio­ned ser­vice. This is a con­tract man­da­ted by data pri­va­cy laws that gua­ran­tees that they pro­cess per­so­nal data of our web­site visi­tors only based on our ins­truc­tions and in com­pli­ance with the GDPR.

Search
Jetzt anrufen
WhatsApp schreiben
Mail verfassen
Contact on WhatsApp
All dates

December 24, 2024, to December 27, 2024: No dermatology consultations or aesthetic treatments.

December 23, 2024, December 30, 2024, and December 31, 2024: Dermatology consultations available.

December 24, 2024, December 27, 2024, and December 28, 2024: Cosmetic treatments available.

December 20, 2024, and December 31, 2024: Cosmetic treatments available.

January 1, 2025, to January 2, 2025: No cosmetic treatments or dermatology consultations.