Data protection

  1. About us

    Kögel Trailer GmbH is responsible for collecting, processing and storing your data. For information about our company, you can read our legal notification at any time.
    Handling your persona data with care is our number one priority. When processing your data, we always adhere to legal provisions and the General Data Protection Regulation (GDPR) as well as any related national provisions.
    This data privacy policy applies to all websites that can be opened under our company domains (www.koegel.comparts.koegel.comwww.koegel-fanshop.com ). If one of our websites redirects you to the website of another operator, separate data protection regulations apply and the relevant site operator is responsible for the content of these regulations.
    We would like to give you a comprehensive overview of the processing of personal data in our company. Below you will find a list of all our services in which we collect and process personal data.
    Where separate or additional conditions apply to individual services or where we explicitly ask you for your consent, we will point this out to you separately before you start using the respective service (for example, for newsletter subscriptions or purchases in our Fan Shop or Parts Shop).
    We also take a variety of security measures to protect your personal data. For example, transmissions between your web browser and our servers always use transport encryption. In addition, we maintain a variety of technical and organisational measures to protect your data at all times.

  2. Why we process your data

    You can use our website without revealing your identity. If you would like to register for one of our personalised services, use our online shop, register for our newsletter or contact us, we will ask for your name and other personal information. It is your free decision whether or not you want to submit this (extended) data. Data that we absolutely need in order to provide our services to you is marked as such.
    Collection and processing of your personal data takes place for the following purposes based on the following legal provisions:
    • Contract initiation in accordance with Art. 6 para. 1 lit. a) and b) GDPR
    • Contract execution in accordance with Art. 6 para. 1 lit. b) GDPR
    • Customer management in accordance with Art. 6 para. 1 lit. b) and c), f) GDPR
    • Communication and data exchange in accordance with Art. 6 para. 1 lit. a), b), c), f) GDPR
    • External presentation and advertising in accordance with Art. 6 para. 1 lit. f) GDPR
    • Implementation of declarations of consent in accordance with Art. 6, para 1 lit. a) GDPR
    • Ensuring the proper operation of a data processing system in accordance with Art. 6 para. 1 lit. c) and f) GDPR
    • Applicant selection procedure as part of human resources management based on Art. 6 para. 1 lit. a), b) of GDPR in conj. with § 26 BDSG New (German Federal Data Protection Act)
  3. What data we collect and process

    We collect different categories of personal data from you. Personal data means any information relating to an identified or identifiable natural person; a natural person is regarded as identifiable, either directly or indirectly, in particular by association with an identifier such as a name. Personal data includes, for example, information such as your name, address, telephone number and date of birth (if provided). Statistical information that cannot be directly or indirectly associated with you – such as the popularity of individual websites or the number of users of a page – is not classed as personal data. Data is collected both directly and indirectly. In both cases, data is collected only to the extent necessary for the purpose; the data will be processed exclusively for the purposes mentioned under point 2. Whether you want to provide us with data that is not necessary in this sense, but is needed by us to optimise our services for you, is at your own discretion. The respective data fields are marked as 'voluntary'.
    Directly collected data includes:
    • Title and name, e.g. to personalise your user account or place an order in our Fan Shop or Parts Shop
    • E-mail address and, if necessary, a password chosen by you to subscribe to our newsletter, use your customer account or contact us via our contact form, for example
    • Address data used to process orders (delivery) placed in our Fan Shop or Parts Shop
    • Payment data for processing the payment of your order
    • Applicant data obtained as part of a job application,
    • Data that you actively and consciously transmit in connection with the use of our services
    • Other data that you voluntarily submit to us, for example, data fields filled by you and marked as 'voluntary'

    In addition, the use of our services indirectly collects data about you:
    • Technical connection data, e.g. the page of our website, your IP address, shortened by the last three digits, date and time the page was opened, terminal used
    • Data collected as part of website tracking and newsletter tracking
    • Data we receive from our service providers when processing orders in the Fan Shop or Parts Shop, e.g. information on payment probabilities and payment disruptions or delivery notifications

    Minors:
    Our website is not intended for minors and we do not knowingly collect personal information from minors.
    If persons under the age of 16 transfer personal data to us, this is only permitted if the parent or guardian has consented or consented to the minor's consent. For this purpose, the contact details of the legal guardian must be communicated to us in accordance with Art. 8, para 2 of GDPR in order to convince us of the consent or consent of the legal guardian. This data and the data of the minor will then be processed in accordance with this data privacy policy.
    If we find that a minor under the age of 16 has sent us personal information without the parent's consent or consent to the consent of the minor, we will promptly delete the information. This section does not apply for applications.

  4. Who has access to your data and to whom we transmit your data

    1. Access
      Access to your personal data stored by us is limited to our employees, and the service providers commissioned by us, who have to deal with this personal data within their remit.
      If third parties have access to your data, we have either obtained the permission for this from you or there is a legal basis for it.
      We also use service providers to provide certain services and process your data (including for hosting, dispatching newsletters, delivering ordered goods, payment processing, sending letters or e-mails as well as updating and analysing databases, securing our web servers and website tracking). If special provisions apply, we have listed them below under each service. The service providers process the data only in accordance with our instructions and have committed themselves to comply with the applicable data protection regulations. All processors have been carefully selected and will have access to your data only to the extent and for the period required for the provision of the services, or to the extent to which you have consented to the processing and use of the data.
    2. Data exchange within the group of companies
      Data exchange within the group of companies to which we belong takes place exclusively within the EU / EEA and is only used for internal administrative purposes. By "group of companies" we mean affiliated companies within the meaning of Art. 4 no. 19 GDPR.
    3. Transmission to third countries and legal basis
      The servers of some of the service providers we use are located in the US and other countries outside the European Union. Companies in these countries are subject to a data protection law that generally does not protect personal data to the same extent as the member states of the European Union do. If your information is processed in a country that does not have a recognised level of data protection such as the European Union, we will use contractual or other recognised means to ensure that your personal data is adequately protected. We will expressly inform you of this in the context of each individual service.
      If a transfer of personal data takes place in third-party countries, it is done on the basis of the adequacy decision of the EU Commission on the EU-US Privacy Shield pursuant to Art. 45 of GDPR or the EU Standard Contract 2010 pursuant to Art. 46 para. 2 lit. c of GDPR in conjunction with the decision of the European Commission dated 05.02.2010 (2010/87 / EU) or according to Art. 49, para. 1 lit. a GDPR.
    4. Transmission to law enforcement agencies
      In exceptional cases, we will provide personal data to law enforcement agencies. This happens by virtue of the relevant statutory provisions such as the Code of Criminal Procedure, the Tax Code, the Money Laundering Act or the State Police Act.
  5. Retention periods

    We store personal data within the scope of statutory provisions or your consent.
    We use the following criteria to determine the actual storage period:
    We store personal data until the purposes for which it was collected no longer apply (for example, when a contractual relationship ends or once the last activity is performed if there is no continuing obligation or if you have revoked your consent for actual processing of the data).
    Personal data is only stored further if
    • legal retention requirements apply (for example, according to the German Taxation Regulation (AO) and Commercial Code (HGB));
    • the data is still required to assert and exercise legal claims or defend against legal claims, for example, based on technological and forensic requirements for repelling attacks on our web servers and the monitoring of these servers;
    • deletion would be against the legitimate interest of the persons involved;
    • or
    • any other exception is applied according to Art. 17 para. 3 of GDPR.
  6. Your rights

    You have a number of statutory rights to which we would like to refer you below. In addition, for all questions regarding personal data collected and processed by us, you can contact our data protection officer at any time using the contact details below.
    1. Right to information and data portability
      You have the right to information about your personal data processed by us at any time.
      If the data processing is based on your consent or in accordance with Art. 6, para. 1 b) of GDPR, you may also request, pursuant to Art. 20, para. 1 of GDPR, to receive your personal data stored in a structured, common and machine-readable format. At your request, we will also forward the data directly to a recipient of your choice.
    2. Right to rectification, restriction and deletion
      Furthermore, in accordance with Art. 16 to 18 of GDPR, you may request that we correct, restrict (block) or delete your personal data if the data has been processed incorrectly by us, if there is a reason for restricting further data processing, or if data processing has become unlawful for various reasons or if its storage is unlawful for other legal reasons. We would like to point out that your right to deletion may be restricted by statutory retention periods.
    3. Right to object
      If our data processing is based exclusively on our legitimate interest in accordance with Art. 6, para 1 f) of GDPR, you can object to this processing in accordance with Art. 21, para. 1 of GDPR. Then we will cease processing your data unless we can demonstrate legitimate grounds for processing that outweigh your interests, rights and freedoms, or the processing is for the purpose of enforcing, pursuing or defending a legal claim. Moreover, you always have the right to revoke use of your data for direct advertising purposes with future effect in accordance with Art. 21 para. 2 of GDPR.
    4. Right of revocation
      If you have allowed us to process your personal data by consent, you have a right of revocation with future effect in accordance with Art. 7 para. 3 of GDPR.
    5. Right to lodge complaints with the supervisory authority
      You are free to lodge a complaint with a regulator if you believe that our processing of your personal data is in breach of the European Data Protection Regulation or other national and international data protection laws.

      The contact details of the responsible regulator are:
      Bayrisches Landesamt für Datenschutz (BayLDA)
      Promenade 27
      91522 Ansbach, Germany
      Telephone: +49 (0) 981 53 1300
      undefinedpoststelle(at)lda.bayern.de
    6. Contact details
      To exercise your rights, you can send us an informal message to the following contacts. Likewise, please direct the revocation of your consent by stating which declaration of consent you wish to revoke to the following contacts:.

      Person responsibleDSB
      Kögel Trailer GmbH
      Am Kögel-Werk 1
      89349 Burtenbach
      Germany
      Tel: +49 8285 88-0
      Fax: +49 8285 88-17905
      Email: undefinedinfo(at)koegel.com
      it.sec GmbH & Co. KG
      Einsteinstr. 55
      89077 Ulm
      Germany
      Tel: +49 731 20589-24
      Email: undefineddatenschutz(at)it-sec.de


  7. Use of our website – profiling, cookies and web tracking

    1. Basic information on cookies and opt-out options
      We use so-called cookies in some areas of our website, for example, in order to recognize the preferences of the visitors and optimise the website design accordingly. This allows easier navigation and a high degree of user-friendliness. Cookies also help us identify particularly popular areas of our website. Cookies are small files that are stored on the hard disk of a visitor’s computer. They allow to keep information for a certain period of time and to identify the visitor's device. For better user guidance and individual performance, we use permanent cookies.
      We also use so-called session cookies, which are automatically deleted when you close your browser. You can set your browser to inform you about the placement of cookies in order to make the use of cookies more transparent. We collect the following technical connection data: The page opened on our website, your IP address shortened by the last three digits, date and time the page was opened, terminal used, browser configuration data. This data is collected to check the authorisation of actions and authentication of the individual requesting the use of our services. Art. 6 para. 1 lit. c) in conjunction with Art. 32 and Art. 6 para. 1 lit. f) of GDPR form the legal basis here. Our legitimate interest is securing our web server to defend against attacks and guarantee the effectiveness of our services, for example. We do not use cookies that are not technically necessary without your express consent and you are entitled to revoke this consent at any time.
      You have already accepted the following declaration in the cookie information on our website:
      This website uses tracking cookies and tracking software to offer you all the functions available on our website and improve your online experience. Refer to our data privacy policy at https://www.koegel.com/en/data-protection/ for more detailed information about the cookies and web tracking processes we use and the consents you have given us. However, all cookies and our tracking software are only activated after you have given us your consent.
      If you exclude the use of cookies completely, you cannot use some of the functions of our website, including the possibility of cookie-based opt-out from tracking. Please accept opt-out cookies for those services that you would like to stop tracking.
      Please also keep in mind that deleting all cookies will result in opt-out cookies being deleted as well. You may have to reset this if necessary. Cookies are also browser-bound, i.e. they must always be set separately for each browser you use on each device you use. The necessary links can be found below in the description of the respective service.
      The following cookies are used by us for a specific purpose, provided you allow this and have not set one or more opt-out cookies:
      Name of the cookiePurposeStorage periodTechnically requiredOption of revoking consent (if cookie is not required for technical purposes)
      PrestaShop-4208bd649f01e3f7729f5d6afc06c2c2 Fan shop user identification At the end of the session Yes (login / content maintenance) See below
      Fe_typyo_user Typo3 user identification At the end of the session Yes (login / content maintenance) See below
      resolution Buffering of screen resolution At the end of the session Yes (styling) See below
      _utma Tracking / Google Analytics 2 Years Tracking See below
      _utmb Tracking / Google Analytics 30 minutes Tracking See below
      _utmc Tracking / Google Analytics At the end of the session Tracking See below
      _utmt Tracking / Google Analytics 10 minutes Tracking See below
      _utmz Tracking / Google Analytics Tracking See below
      _ga Tracking / Google Analytics
      _gat Tracking / Google Analytics
      authenticationCookie authenticationCookie is used by ASP.NET for authentication 1 hour Yes see below
      cookieconsent_status cookieconsent_status is used by the Cookie Consent Javascript Plugin 1 year Yes see below
      CurrentCustomerId CurrentCustomerId is used by us to save the current customer 1 day Yes see below
      XSRF-Token XSRF token and XSRF-V is also used to prevent cross forgery 1 year Yes see below
      XSRF-V XSRF token and XSRF-V is also used to prevent cross forgery 1 year Yes see below
      UMB_UCONTEXT UMB_UCONTEXT is for authentication for Umbraco Backend 4 hours Yes see below
      CART_ID CART_ID is used by us to save the shopping cart 1 day Yes see below
      ARRAffinity ARRAffinity is used by Azure IIS to make the assignment to the respective Web app instances 1 year Yes see below
      __RequestVerificationToken __RequestVerificationToken is used to prevent cross forgery 1 year Yes see below
      ai_user ai_user and ai_session is used by Microsoft Azure Application Insights to get client-side logs 30 minutes Yes see below
      ai_session ai_user and ai_session is used by Microsoft Azure Application Insights to get client-side logs 1 year Yes see below
    2. Google Analytics
      This website uses Google Analytics, a web analytics service provided by Google LLC. (“Google”). Google Analytics uses "cookies", which are text files placed on your computer to help the website analyse how visitors use the site. The information generated by the cookie about your use of the website will normally be transmitted to a Google server in the USA and stored there. In case of activation of the IP anonymity on this website, however, your IP address will be abbreviated by Google beforehand within Member States of the European Union or in other countries that are contracting parties of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and abbreviated there. Google will use this information on our behalf for the purpose of evaluating your use of the website, in order to compile reports on website activity and to provide the website operator with other services relating to website activity and Internet usage. The IP address transmitted by your browser within the sphere of Google Analytics will not be associated with any other data held by Google. One way to disallow web analytics through Google Analytics is to set a so-called opt-out cookie, which instructs Google not to store or use your data for web analysis purposes. Please note that this solution prevents the web analysis as long as the opt-out cookie is stored by the browser. If you want to set the opt-out cookie now, please click heree Opens external link in new windowhttps://developers.google.com/analytics/devguides/collection/gajs/?hl=en#disable.
      You may also refuse the use of cookies by selecting the appropriate settings on your browser; however, please note that if you do this, you may not be able to use the full functionality of this website. Furthermore, you can prevent Google from collecting and using the data relating to your use of the website generated by the cookie (incl. your IP address) by downloading and installing the browser plug-in available under the following link. The current link is: Opens external link in new windowhttp://tools.google.com/dlpage/gaoptout?hl=en.

      Data recipient: Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

      Privacy-Shield: Opens external link in new windowhttps://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
    3. Google Tag Manager
      Google Tag Manager is a Google product that allows us to manage website tags of applications such as Google Analytics via an interface. Tag Manager is a cookie-free domain and does not collect any personal data. 
    4. Google Maps
      Our website uses the ‘Google Maps’ service by Google, to enable you to find a dealer or plan routes, for example.
      When opening Google Maps on this website, data is transferred to Google, e.g. your current location. The Google data protection regulations apply for this service (Opens external link in new windowhttps://www.google.com/intl/en_en/policies/privacy/), supplemented by special data protection regulations for Google Maps (Opens external link in new windowhttps://www.google.com/intl/en_en/help/terms_maps.html).
      You can prevent Google Maps from starting by activating a JavaScript blocker to selectively prevent the execution of the JavaScript code used; alternatively you can completely deactivate the execution of JavaScript in your browser settings.

      Data recipient: Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA,

      Privacy-Shield: Opens external link in new windowhttps://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
    5. Youtube video, embedded via iFrame in expanded data protection mode
      We use YouTube, a service provided by Google, to show you video content. To protect your privacy, we have activated expanded data protection mode.
      YouTube also uses cookies to collect information about visitors to its website. YouTube uses them to collect video statistics, prevent fraud, and improve usability. Viewing a video usually also establishes a connection with the Google DoubleClick network. If you start the video, this could trigger further data processing, especially if you are already logged in to YouTube. We have no influence on that.
      By pressing the video start button, you agree to allow YouTube LLC to collect your data:
      Further information about data protection on YouTube is available in its privacy statement (Opens external link in new windowhttp://www.youtube.com/t/privacy_at_youtube).

      Data recipient: Youtube LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

      Privacy-Shield: Opens external link in new windowhttps://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active 
    6. Social Media Buttons
      Our website uses social media buttons (Facebook, Twitter, LinkedIn, Instagram, YouTube) to allow you to interact with third parties.
      These social media buttons are not integrated as plug-ins via a so-called iFrame, but stored as links. Pressing a social media button immediately redirects you to the website of the relevant provider. The corresponding provider is then responsible for complying with the data protection regulations as well as the correctness, validity and completeness of the data processing information provided there as outlined in Art. 4 No. 17 of GDPR.
    7. Facebook-Connect
      n/a
    8. Cookie Consent
      Cookie Consent is a free JavaScript plugin for alerting users about the use of cookies on the Kögel Parts Shop (URL: Opens external link in new windowhttps://parts.koegel.com). Further information can be found at Cookie Consent by Insites (URL: Opens external link in new windowhttps://cookieconsent.insites.com/).
  8. Additional information and provisions for individual services

    1. Newsletter
      At your express request, we will send you our newsletter on the topics you selected as well as information about our company. Please note that we can only activate the service once you have expressly confirmed your request again as part of our double opt-in procedure.
      Personal data collected during your newsletter registration is used exclusively to send and personalise the newsletter (for example, to address you by name). You can revoke any consent that allows us to store the personal data you provided in order to receive a copy of our newsletter at any time with future effect. Each newsletter contains a corresponding link that you can use to revoke your consent; alternatively, you can also contact us directly so that we can implement your request to revoke your consent. We have provided details of the consent you have given us in the double opt-in e-mail.

      Newsletter utilisation analysis
      Our newsletter contains tracking pixels. A tracking pixel is an invisible graphic element in HTML e-mails used to create a log file record when the e-mail is opened as well as a record of the links activated from the newsletter with subsequent analysis. This allows us to perform a statistical analysis to evaluate the success of our newsletter campaigns and optimise our newsletter to present topics and offers that match your interests more closely, for example.
      Personal data collected in this way is processed by our service provider, named below.
      If you do not agree to this, you can cancel your subscription to the newsletter at any time by clicking on the link in the newsletter.

      Data recipient: 
      • CleverReach GmbH & Co. KG, Mühlenstrasse 43, 26180 Rastede, Germany.
      • Newsletter2Go GmbH, Köpenicker Str. 126, D-10179 Berlin
    2. Contact form
      Data that you submit to us via our contact form will be processed for the purposes of communication and data exchange, so as to respond to your specific request. This data is stored as long as its processing is required for these purposes or until expiration of any subsequent retention periods.
    3. Competition
      From time to time, you will have the opportunity to take part in competitions or similar campaigns on our website. During these campaigns, the personal data required in from the entry form may be collected and stored for processing. Data that is not essential for running the competition, but which allows us to notify you that you have won, for example, is marked explicitly as voluntary information.  Personal details disclosed to us during a competition campaign of this kind is used exclusively to carry out the campaign (in the case of a competition, notify winners, select and send the prize, for example). At the end of the campaign, the data of participants who have not won is deleted immediately and the data of winning participants is deleted when the statutory retention period expires.
    4. Online application procedures
      You have the option of submitting you application to us via e-mail or contacting us by telephone, mail or via WhatsApp. Regulator bodies currently consider the use of WhatsApp as harmless, in particular because regulatory authorities and the BfDI have not provided any official data privacy test results relating to the WhatsApp service. You can therefore contact us using the suggested alternative(s) to WhatsApp, e.g. post or e-mail, which are considered harmless from a data protection perspective. These alternatives can be used for instances where you wish to send us application documents that contain particularly sensitive data.
      If WhatsApp is used during the application process, we will store your first name, surname and the mobile number saved in your WhatsApp account as well as the information in your application documents. Additional data is only collected if it is sent as part of the application process, possibly along other channels.
      You can revoke your consent for your data and mobile number to be stored and then used as part of the application process at any time. You can revoke consent in a WhatsApp message or via e-mail using the above contact details.
      Your electronic application data is received by the relevant human resources department and forwarded only to the specialist department responsible for the job or persons instructed to process applications. All individuals involved in the application process shall handle your application documents with due care and absolute confidentiality.
      At the end of the application process, we will retain your application documents for another 3 months and then delete or destroy any copies, unless you have signed an employment contract with us. If we wish to include your application documents in our applicant pool, we will contact you accordingly. In the notification, you can actively give us your consent to continue storing your documents.
      Please note that any applications sent to us via e-mail are forwarded to us in unencrypted format. We therefore recommend using encryption software. Furthermore, we cannot guarantee that any data provided through WhatsApp is encrypted because WhatsApp is responsible for encryption and we cannot check this.
    5. Online-Shops
      We offer a Parts Shop on our website, where you can purchase spare parts, as well as a fan shop with further offers for all things Kögel.
      We use the data collected there to execute the contract, in particular to enable the purchase and delivery of products and execute payments.
      Depending on the selected shipping method, we will transfer the necessary data to the selected shipping service provider for the specific purpose of shipping and delivery – including, as far as you have given your consent, your email address for the purpose of making shipping notification, agreeing a delivery time or sending tracking information.
      We also transfer the data required to execute payments and perform risk management, if necessary, to the payment service provider you selected. The following additional information and conditions apply here:
      1. Paypal payments
        You can pay for products in our Online Shop using the payment service provider PayPal. Payments are processed either via your PayPal account or using the credit card or bank account linked to your PayPal account. Furthermore, PayPal also offers buyer protection and trust services. When PayPal is selected as a payment service provider in the Online Shop, data is transferred automatically to PayPal. If you decide to pay using PayPal, you explicitly consent to transfer your personal data (first name and surname, address, e-mail address, IP address, telephone number(s), order and delivery information) for the purpose of executing payments and preventing fraud.
        Data is not only exchanged for the purpose of executing payments, but also for identification, fraud prevention and reducing our default risk, which is why data relating to your financial situation and past purchasing and payment behaviour may be exchanged. In this context, Klarna also exchanges data with credit agencies, provided that they have a legitimate interest and do not conflict with the legitimate interests of the data subject.
        The data may be passed on to affiliated companies; this also applies for downstream service providers (processors, mutually responsible persons and third parties, if required to execute the contract).
        You may revoke this consent from PayPal at any time with future effect. Revoking your consent has no effect on previously transmitted data.

        You can read the valid PayPal data protection regulations at Opens external link in new windowhttps://www.paypal.com/en/webapps/mpp/ua/privacy-full abgerufen werden.

        Data recipient: PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg.
      2. Credit card payments
        You can use your credit card to pay for products in our Online Shop via payment service provider Heidelpay GmbH. You will need to enter all the required credit card details directly into an embedded form of our payment service provider.
        When the ‘credit card’ payment method is selected, data is transmitted automatically to Heidelpay GmbH. If you decide to pay using a credit card, you explicitly consent to transfer your personal data (first name and surname, address, purchase price) for the purpose of executing payments and preventing fraud.

        The data may be passed on to affiliated companies; this also applies for downstream service providers (processors, mutually responsible persons and third parties, if required to execute the contract). You may revoke this consent from Heidelpay GmbH at any time with future effect. Revoking your consent has no effect on previously transmitted data.

        Data recipient: Heidelpay GmbH, Vangerowstrasse 18, 69115 Heidelberg, Germany.
      3. Immediate transfer payments
        You can pay for products in our Online Shop immediately using the immediate payment service provider SOFORT GmbH.
        With this payment method, confirmation of the payment is sent to us, the seller, in real time so that we can start processing your order immediately.
        When the ‘immediate transfer’ payment method is selected, data is transmitted automatically to SOFORT GmbH. If you decide to pay by immediate transfer, you explicitly consent to transfer your personal data (first name and surname, address, e-mail address, IP address, telephone number(s), bank details, PIN, TAN, purchase price) for the purpose of executing payments and preventing fraud.
        Data is not only exchanged for the purpose of executing payments, but also for identification and fraud prevention, which is why data relating to your financial situation and past purchasing and payment behaviour may be exchanged. In this context, SOFORT GmbH also exchanges data with credit agencies, provided that they have a legitimate interest and do not conflict with the legitimate interests of the data subject.
        The data may be passed on to affiliated companies; this also applies for downstream service providers (processors, mutually responsible persons and third parties, if required to execute the contract).
        You may revoke this consent from SOFORT GmbH at any time with future effect. Revoking your consent has no effect on previously transmitted data.

        You can read the valid SOFORT GmbH data protection regulations at Opens external link in new windowhttps://www.sofort.com/ger-DE/datenschutzerklaerung-sofort-gmbh/.

        Data recipient: SOFORT GmbH, Fussbergstrasse 1, 82131 Gauting, Germany.
    6. Customer account
      On our website, you have the possibility of creating a personal customer account. The customer account allows you to personalise and link services you select on our website as well as save your favourite settings.
    7. Data processing for direct advertising purposes
      Mail advertising
      Within the legally permitted framework, we may also use your name and the postal address we have on record to send you advertising literature for our own products. Art. 6 para. 1 lit. f) forms the legal basis here in conjunction with recital 47 of GDPR. Our legitimate interest is the promotion of sales and demand among our existing customers. Needless to say, you can revoke your consent for us to process your data for advertising purposes at any time with future effect. Sending a written message to the above contact details is sufficient. We will then remove your details from our mail distribution list. We will then store the data confirming the revocation of your consent for a further 6 years according to Art. 17 para. 3 lit. e) of GDPR. During this time, however, your personal data will be blocked from further processing.

      Telephone advertising
      If you are a business customer and provided you have a presumed interest, we may also use your name, company affiliation and telephone number we have on record to inform you about our own products within the legally permitted framework. Art. 6 para. 1 lit. f) forms the legal basis here in conjunction with recital 47 of GDPR and § 7 para. 2 No. 2 of the German Law Against Unfair Competition. Our legitimate interest is the promotion of sales and demand among our existing business customers. Needless to say, you can revoke your consent for us to process your data for advertising purposes at any time with future effect. Sending a written message to the above contact details is sufficient. We will then remove your details from our mail distribution list. We will then store the data confirming the revocation of your consent for a further 6 years according to Art. 17 para. 3 lit. e) of GDPR. During this time, however, your personal data will be blocked from further processing.