Your Cart

Your cart is empty

Browse products and add items to your cart

Privacy Policy

Data protection has a particularly high priority for MellMed (hereinafter: “Provider”) The use of the

website of the Provider is possible without any indication of personal data. However, if a data subject

wants to use special services of our website, processing of personal data could become necessary. If

the processing of personal data is necessary and if there is no legal basis for such processing, we

generally obtain the consent of the data subject.

The processing of personal data, such as the name, address, e-mail address, or telephone number of

a data subject shall always be in line with the country-specific data protection regulations applicable

to the Provider. By means of this data protection declaration, our enterprise would like to inform the

public about the type, scope and purpose of the personal data we collect, use and process.

Furthermore, data subjects are informed of their rights by means of this data protection declaration.

As the controller, the Provider has implemented numerous technical and organizational measures to

ensure the most complete protection of personal data processed through this website. Nevertheless,

Internet-based data transmissions can always have security vulnerabilities, so that absolute

protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data

to us by alternative means, for example by telephone.

1. Definitions

The Provider’s data protection declaration is based on the terms used by the European

Directive and Ordinance when adopting the General Data Protection Regulation (DS-GVO).

Our data protection declaration should be easy to read and understand for the public as

well as for our customers and business partners. To ensure this, we would like to explain

the terms used in advance.

We use the following terms, among others, in this privacy policy:

1.1. Personal data

Personal data means any information relating to an identified or identifiable natural person

(hereinafter "data subject"). An identifiable natural person is one who can be identified,

directly or indirectly, in particular by reference to an identifier such as a name, an

identification number, location data, an online identifier or to one or more factors specific

to the physical, physiological, genetic, mental, economic, cultural or social identity of that

natural person.

1.2. Person concerned

Data subject means any identified or identifiable natural person whose personal data are

processed by the controller.

1.3. Processing

Processing is any operation or set of operations which is performed upon personal data,

whether or not by automatic means, such as collection, recording, organisation, filing,

storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission,

dissemination or otherwise making available, alignment or combination, restriction, erasure

or destruction.

1.4. Restriction of processing


2

Restriction of processing is the marking of stored personal data with the aim of limiting

their future processing.

1.5. Profiling

Profiling is any form of automated processing of personal data which consists of using such

personal data to evaluate certain personal aspects relating to a natural person, in particular

to analyse or predict aspects relating to that natural person's performance at work,

economic situation, health, personal preferences, interests, reliability, behaviour, location

or change of location.

1.6. Pseudonymisation

Pseudonymisation is the processing of personal data in such a way that the personal data

can no longer be attributed to a specific data subject without the use of additional

information, provided that such additional information is kept separately and is subject to

technical and organisational measures which ensure that the personal data are not

attributed to an identified or identifiable natural person.

1.7. Controller or person responsible for the processing

The controller or person responsible for processing is the natural or legal person, public

authority, agency or other body which alone or jointly with others determines the purposes

and means of the processing of personal data. Where the purposes and means of such

processing are determined by Union or Member State law, the controller or the specific

criteria for its designation may be provided for under Union or Member State law.

1.8. Processor

Processor means a natural or legal person, public authority, agency or other body which

processes personal data on behalf of the controller.

1.9. Receiver

A recipient is a natural or legal person, public authority, agency or other body to whom

personal data are disclosed, whether or not a third party. However, public authorities that

may receive personal data in the context of a specific investigative task under Union or

Member State law shall not be considered as recipients.

1.10. Third

Third party means a natural or legal person, public authority, agency or other body other

than the data subject, the controller, the processor and the persons authorised to process

the personal data under the direct responsibility of the controller or the processor.

1.11. Consent

Consent shall mean any freely given specific and informed indication of the data subject's

wishes in the form of a statement or other unambiguous affirmative act by which the data

subject signifies his or her agreement to the processing of personal data relating to him or

her.

2. Name and address of the controller


3

The person responsible within the meaning of the General Data Protection Regulation,

other data protection laws applicable in the Member States of the European Union and

other provisions of a data protection nature is:

MellMed

Forest road 32

53577 Neustadt (Wied)

Germany


E-mail: sarhinkmella@hotmail.de

Website: www.MellMed.com


3. Cookies

The internet pages of the Provider use cookies. Cookies are text files that are stored on a

computer system via an internet browser.

Numerous websites and servers use cookies. Many cookies contain a so-called cookie ID. A

cookie ID is a unique identifier of the cookie. It consists of a string of characters by which

internet pages and servers can be assigned to the specific internet browser in which the

cookie was stored. This enables the visited Internet pages and servers to distinguish the

individual browser of the data subject from other Internet browsers that contain other

cookies. A specific internet browser can be recognised and identified via the unique cookie

ID.

Through the use of cookies, the Provider can provide the users of this website with more

user-friendly services that would not be possible without the cookie setting.

By means of a cookie, the information and offers on our website can be optimised in the

sense of the user. As already mentioned, cookies enable us to recognise the users of our

website. The purpose of this recognition is to make it easier for users to use our website.

For example, the user of a website that uses cookies does not have to re-enter his or her

access data each time he or she visits the website, because this is done by the website and

the cookie stored on the user's computer system. Another example is the cookie of a

shopping basket in an online shop. The online shop remembers the items that a customer

has placed in the virtual shopping basket via a cookie.

The data subject can prevent the setting of cookies by our website at any time by means of

an appropriate setting of the Internet browser used and thus permanently object to the

setting of cookies. Furthermore, cookies that have already been set can be deleted at any

time via an internet browser or other software programmes. This is possible in all common

internet browsers. If the data subject deactivates the setting of cookies in the Internet

browser used, not all functions of our website may be fully usable.


4. Collection of general data and information


4

The website of the Provider collects a series of general data and information each time a

data subject or automated system accesses the website. This general data and information

is stored in the log files of the server. The following data may be collected: (1) the browser

types and versions used, (2) the operating system used by the accessing system, (3) the

website from which an accessing system accesses our website (so-called referrer), (4) the

sub-websites which are accessed via an accessing system on our website, (5) the date and

time of access to the website, (6) an Internet protocol address (IP address), (7) the Internet

service provider of the accessing system and (8) other similar data and information that

serve to avert danger in the event of attacks on our information technology systems.

When using these general data and information, the Provider does not draw any

conclusions about the data subject. Rather, this information is needed (1) to deliver the

contents of our website correctly, (2) to optimise the contents of our website and the

advertising for these, (3) to ensure the long-term functionality of our information

technology systems and the technology of our website, and (4) to provide law enforcement

authorities with the information necessary for prosecution in the event of a cyber attack.

Therefore, the Provider evaluates these anonymously collected data and information on

one hand statistically and on the other hand with the aim of increasing the data protection

and data security of our enterprise, and ultimately ensuring an optimal level of protection

for the personal data we process. The anonymous data of the server log files are stored

separately from any personal data provided by a data subject.


5. Registration on our website

The data subject has the possibility to register on the website of the controller by providing

personal data. The personal data that is transmitted to the data controller in this context

results from the respective input mask used for the registration. The personal data entered

by the data subject are collected and stored exclusively for internal use by the controller

and for its own purposes. The controller may arrange for the data to be transferred to one

or more processors, for example a parcel service Provider, who will also use the personal

data exclusively for an internal use attributable to the controller.

By registering on the website of the controller, the IP address assigned by the Internet

service provider (ISP) of the data subject, the date and the time of registration are also

stored. The storage of this data takes place against the background that only in this way can

the misuse of our services be prevented and, if necessary, this data makes it possible to

clarify criminal offences that have been committed. In this respect, the storage of this data

is necessary for the protection of the data controller. As a matter of principle, this data is

not passed on to third parties unless there is a legal obligation to pass it on or the passing

on serves the purpose of criminal prosecution.

The registration of the data subject by voluntarily providing personal data serves the

purpose of the controller to offer the data subject content or services which, due to the

nature of the matter, can only be offered to registered users. Registered persons are free to

modify the personal data provided during registration at any time or to have it completely

deleted from the data of the controller.

The controller shall provide any data subject at any time, upon request, with information

on what personal data is stored about the data subject. Furthermore, the controller shall

correct or delete personal data at the request or indication of the data subject, provided

that this does not conflict with any statutory retention obligations. The entire staff of the

controller shall be available to the data subject as contact persons in this context.


5


6. Contact option via the website

Based on statutory provisions, the website of the Provider contains data that enable a quick

electronic contact to our enterprise, as well as direct communication with us, which also

includes a general address of the so-called electronic mail (e-mail address). If a data subject

contacts the controller by e-mail or by using a contact form, the personal data transmitted

by the data subject will be stored automatically. Such personal data transmitted on a

voluntary basis by a data subject to the controller will be stored for the purposes of

processing or contacting the data subject. This personal data will not be disclosed to third

parties.

7. Comment function in the blog on the website

The Provider offers users the possibility to leave individual comments on individual blog

posts on a blog, which is located on the website of the controller. A blog is a portal

maintained on a website, usually publicly viewable, in which one or more persons, called

bloggers or web bloggers, can post articles or write down thoughts in so-called blogposts.

The blogposts can usually be commented on by third parties.

If a data subject leaves a comment on the blog published on this website, in addition to the

comments left by the data subject, information on the time of comment entry and the user

name (pseudonym) chosen by the data subject will be stored and published. Furthermore,

the IP address assigned by the Internet service provider (ISP) of the person concerned is

also logged. This storage of the IP address takes place for security reasons and in the event

that the person concerned violates the rights of third parties by posting a comment or

posts illegal content. The storage of this personal data is therefore in the controller's own

interest, so that the controller could exculpate itself if necessary in the event of an

infringement. The personal data collected will not be disclosed to third parties, unless such

disclosure is required by law or serves the legal defence of the controller.

8. Routine deletion and blocking of personal data

The controller shall process and store personal data of the data subject only for the time

necessary to achieve the purpose of storage or where provided for by the European

Directive and Regulation or other legislator in laws or regulations to which the controller is

subject.

If the purpose of storage no longer applies or if a storage period prescribed by the

European Directive and Regulation Body or another competent legislator expires, the

personal data will be routinely blocked or deleted in accordance with the statutory

provisions.


9. Rights of the data subject

9.1. Right to confirmation

Every data subject has the right, granted by the European Directive and Regulation, to

obtain confirmation from the controller as to whether personal data concerning him or her

are being processed. If a data subject wishes to exercise this right, he or she may, at any

time, contact any employee of the controller.


6


9.2. Right to information

Any person concerned by the processing of personal data has the right granted by the

European Directive and Regulation to obtain from the controller, at any time and free of

charge, information about the personal data stored about him or her and a copy of that

information. Furthermore, the European legislator has granted the data subject access to

the following information:

 the processing purposes

 the categories of personal data that are processed

 the recipients or categories of recipients to whom the personal data have been or will

be disclosed, in particular in the case of recipients in third countries or international

organisations

 if possible, the planned duration for which the personal data will be stored or, if this is

not possible, the criteria for determining this duration

 the existence of a right to obtain the rectification or erasure of personal data

concerning them or to obtain the restriction of processing by the controller or a right

to object to such processing

 the existence of a right of appeal to a supervisory authority

 if the personal data are not collected from the data subject: All available information

on the origin of the data

 the existence of automated decision-making, including profiling, pursuant to Article

22(1) and (4) of the GDPR and, at least in these cases, meaningful information about

the logic involved and the scope and intended effects of such processing for the data

subject

Furthermore, the data subject has the right to be informed whether personal data have

been transferred to a third country or to an international organisation. If this is the case,

the data subject also has the right to obtain information on the appropriate safeguards in

connection with the transfer.

If a data subject wishes to exercise this right of access, he or she may, at any time, contact

any employee of the controller.

9.3. Right of rectification

Any person concerned by the processing of personal data shall have the right granted by

the European Parliament and the Council to obtain the rectification without delay of

inaccurate personal data concerning him or her. Furthermore, the data subject has the right

to request the completion of incomplete personal data, including by means of a

supplementary declaration, taking into account the purposes of the processing.

If a data subject wishes to exercise this right of rectification, he or she may, at any time,

contact any employee of the controller.

9.4. Right to erasure (right to be forgotten)

Any person concerned by the processing of personal data shall have the right, granted by

the European Parliament and the Council, to obtain from the controller the erasure without

delay of personal data concerning him or her, where one of the following grounds applies

and insofar as the processing is not necessary:


7

 The personal data were collected or otherwise processed for purposes for which they

are no longer necessary.

 The data subject revokes the consent on which the processing was based pursuant to

Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR and there is no other legal

basis for the processing.

 The data subject objects to the processing pursuant to Article 21(1) of the GDPR and

there are no overriding legitimate grounds for the processing, or the data subject

objects to the processing pursuant to Article 21(2) of the GDPR.

 The personal data have been processed unlawfully.

 The deletion of the personal data is necessary for compliance with a legal obligation

under Union or Member State law to which the controller is subject.

 The personal data was collected in relation to information society services offered

pursuant to Art. 8(1) DS-GVO.

If one of the aforementioned reasons applies, and a data subject wishes to arrange for the

deletion of personal data stored by the Provider, he or she may, at any time, contact any

employee of the controller. The Provider's employee shall arrange for the deletion request

to be complied with immediately.

If the personal data have been made public by the Provider and our company as the

controller is obliged to erase the personal data pursuant to Article 17 (1) of the Data

Protection Regulation, the Provider shall implement reasonable measures, including

technical measures, taking into account the available technology and the cost of

implementation, in order to inform other data controllers which process the published

personal data that the data subject has requested from those other data controllers the

erasure of all links to the personal data or copies or replications of the personal data, unless

the processing is necessary. The employee of the Provider will arrange the necessary in

individual cases.

9.5. Right to restrict processing

Any person concerned by the processing of personal data has the right, granted by the

European Directive and Regulation, to obtain from the controller the restriction of

processing where one of the following conditions is met:

 The accuracy of the personal data is contested by the data subject for a period

enabling the controller to verify the accuracy of the personal data.

 The processing is unlawful, the data subject objects to the erasure of the personal data

and requests instead the restriction of the use of the personal data.

 The controller no longer needs the personal data for the purposes of processing, but

the data subject needs it for the establishment, exercise or defence of legal claims.

 The data subject has objected to the processing pursuant to Article 21(1) of the GDPR

and it is not yet clear whether the legitimate grounds of the controller override those

of the data subject.

If one of the aforementioned conditions is met, and a data subject wishes to request the

restriction of personal data stored by the Provider, he or she may, at any time, contact any

employee of the controller. The employee of the Provider will arrange the restriction of the

processing.

9.6. Right to data portability


8

Any person concerned by the processing of personal data has the right, granted by the

European Directive and Regulation, to receive the personal data concerning him or her,

which have been provided by the data subject to a controller, in a structured, commonly

used and machine-readable format. The data subject shall also have the right to transmit

such data to another controller without hindrance from the controller to whom the

personal data have been provided, provided that the processing is based on consent

pursuant to Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR or on a contract

pursuant to Article 6(1)(b) of the GDPR and the processing is carried out by automated

means, unless the processing is necessary for the performance of a task carried out in the

public interest or in the exercise of official authority vested in the controller.

Furthermore, when exercising his or her right to data portability pursuant to Article 20(1) of

the GDPR, the data subject shall have the right to obtain that the personal data be

transferred directly from one controller to another controller, to the extent that this is

technically feasible and provided that this does not adversely affect the rights and

freedoms of other individuals.

In order to assert the right to data portability, the data subject may at any time contact any

employee of the Provider.

9.7. Right of appeal

Any person affected by the processing of personal data shall have the right granted by the

European Directive and Regulation to object at any time, on grounds relating to his or her

particular situation, to the processing of personal data concerning him or her which is

carried out on the basis of Article 6(1)(e) or (f) of the GDPR. This also applies to profiling

based on these provisions.

The Provider shall no longer process the personal data in the event of the objection, unless

we can demonstrate compelling legitimate grounds for the processing which override the

interests, rights and freedoms of the data subject, or for the assertion, exercise or defence

of legal claims.

If the Provider processes personal data for the purpose of direct marketing, the data

subject shall have the right to object at any time to processing of personal data for such

marketing. This also applies to profiling insofar as it is related to such direct marketing. If

the data subject objects to the Provider to the processing for direct marketing purposes,

the Provider will no longer process the personal data for these purposes.

In addition, the data subject has the right, on grounds relating to his or her particular

situation, to object to processing of personal data concerning him or her which is carried

out by the Provider for scientific or historical research purposes, or for statistical purposes

pursuant to Article 89(1) of the Data Protection Regulation, unless such processing is

necessary for the performance of a task carried out in the public interest.

In order to exercise the right to object, the data subject may directly contact any employee

of the Provider or another employee. The data subject is also free to exercise his/her right

to object by means of automated procedures using technical specifications in the context of

the use of information society services, notwithstanding Directive 2002/58/EC.

9.8. Automated decisions in individual cases including profiling


9

Any data subject concerned by the processing of personal data shall have the right, granted

by the European Parliament and the Council, not to be subject to a decision based solely on

automated processing, including profiling, which produces legal effects concerning him or

her or similarly significantly affects him or her, unless the decision (1) is necessary for

entering into, or the performance of, a contract between the data subject and the

controller, or (2) is authorised by Union or Member State law to which the controller is

subject and that law contains suitable measures to safeguard the data subject's rights and

freedoms and legitimate interests, or (3) is based on the data subject's explicit consent.

If the decision (1) is necessary for entering into, or the performance of, a contract between

the data subject and the data controller, or (2) it is made with the data subject's explicit

consent, the Provider shall implement suitable measures to safeguard the data subject's

rights and freedoms and legitimate interests, which include at least the right to obtain the

data subject's involvement on the part of the controller, to express his or her point of view

and to contest the decision.

If the data subject wishes to exercise the rights concerning automated decisions, he or she

may, at any time, contact any employee of the controller.

9.9. Right to revoke consent under data protection law

Every person affected by the processing of personal data has the right, granted by the

European Directive and Regulation-maker, to withdraw consent to the processing of

personal data at any time.

If the data subject wishes to exercise the right to withdraw consent, he or she may, at any

time, contact any employee of the controller.


10. Special data protection provisions

10.1. Privacy policy on the use and application of AddThis

The controller has integrated components of the company AddThis on this website.

AddThis is a so-called bookmarking Provider. The service enables a simplified bookmarking

of Internet pages via buttons. By moving the mouse over the AddThis component or by

clicking on it, a list of bookmarking and sharing services is displayed. AddThis is used on

more than 15 million websites and the buttons are displayed more than 20 billion times a

year, according to the operating company.

The operating company of AddThis is AddThis, Inc. 1595 Spring Hill Road, Suite 300, Vienna,

VA 22182, USA.

Each time one of the individual pages of this website operated by the data controller is

accessed and on which an AddThis component has been integrated, the internet browser

on the information technology system of the data subject is automatically prompted by the

respective AddThis component to download data from the website www.addthis.com. The

data subject's internet browser automatically receives the AddThis component. As part of

this technical procedure, AddThis receives knowledge about the visit and which specific

individual page of this website is used by the information technology system used by the

data subject. Furthermore, AddThis obtains knowledge of the IP address of the computer

system used by the data subject assigned by the Internet service provider (ISP), the browser

type, the browser language, the website accessed before our website, the date and the


10

time of the visit to our website. AddThis uses this data to create anonymised user profiles.

The data and information transmitted to AddThis in this way enable AddThis itself and the

companies associated with AddThis or its partner companies to target visitors to the

controller's website with personalised and interest-based advertising.

AddThis displays personalised and interest-based advertising on the basis of a cookie set by

the company. This cookie analyses the individual surfing behaviour of the computer system

used by the person concerned. The cookie stores the visits to Internet pages originating

from the computer system.

The data subject can prevent the setting of cookies by our website, as already described

above, at any time by means of an appropriate setting of the Internet browser used and

thus permanently object to the setting of cookies. Such a setting of the Internet browser

used would also prevent AddThis from setting a cookie on the information technology

system of the data subject. In addition, cookies already set by AddThis can be deleted at

any time via an internet browser or other software programmes.

The data subject also has the option to permanently object to the processing of personal

data by AddThis. To do so, the data subject must press the opt-out button under the link

www.addthis.com/privacy/opt-out, which sets an opt-out cookie. The opt-out cookie set

with the objection is stored on the information technology system used by the data subject.

If the cookies on the data subject's system are deleted after an objection, the data subject

must call up the link again and set a new opt-out cookie.

However, with the setting of the opt-out cookie, there is the possibility that the internet

pages of the controller are no longer fully usable for the data subject.

The applicable privacy policy of AddThis can be found at www.addthis.com/privacy/privacy-

policy.

10.2. Privacy policy on the use and application of AdJug

The controller has integrated components of AdJug on this website. AdJug is an advertising

exchange platform which mediates online advertising spaces (banner advertising).

The operating company of AdJug is AdJug GmbH, Bayerstraße 69, 80335 Munich, Germany.

AdJug sets a cookie. Furthermore, each time one of the individual pages of this website

operated by the data controller is called up and on which an AdJug component has been

integrated, the Internet browser on the data subject's information technology system is

automatically caused by the respective AdJug component to transmit data to AdJug for the

purpose of displaying advertisements. As part of this technical procedure, AdJug receives

knowledge that our website has been accessed by the information technology system used

by the data subject. The data transmitted to AdJug as part of the technical procedure is

used for billing purposes in relation to the advertisements displayed.

The data subject can prevent the setting of cookies by our website, as already described

above, at any time by means of an appropriate setting of the Internet browser used and

thus permanently object to the setting of cookies. Such a setting of the Internet browser

used would also prevent AdJug from setting a cookie on the information technology system

of the data subject. In addition, cookies already set by AdJug can be deleted at any time via

an internet browser or other software programmes.


11

Furthermore, the data subject has the possibility to object to and prevent the collection of

data generated by the AdJug cookie and related to a use of this website as well as the

processing of such data by AdJug. To do so, the data subject must press the consumer

cookie opt-out link at www.de.adjug.com/datenschutz.html, which sets an opt-out cookie.

The opt-out cookie set with the objection is stored on the information technology system

used by the data subject. If the cookies on the data subject's system are deleted after an

objection, the data subject must call up the link again and set a new opt-out cookie.

However, with the setting of the opt-out cookie, there is the possibility that the internet

pages of the controller are no longer fully usable for the data subject.

AdJug's applicable privacy policy can be found at www.de.adjug.com/datenschutz.html.

10.3. Privacy policy on the use and application of Adobe Analytics (Omniture) / Adobe

Marketing Cloud

The controller has integrated components of the company Adobe on this website. Adobe

Analytics (Omniture) or the Adobe Marketing Cloud (hereinafter referred to as "Omniture")

is a tool that enables more efficient online marketing as well as web analysis. Omniture is a

part of the Adobe Marketing Cloud. The Adobe Marketing Cloud enables real-time analyses

of visitor flows on websites. The real-time analyses include project reports and allow ad-hoc

analysis of website visitors. Customer interactions are presented in a way that gives the

controller a better overview of the online activities of the users of that website by

displaying and reporting the data in simple and interactive dashboards. This enables the

controller to receive information in real time and thereby identify problems more quickly.

The operator of these services is Adobe Systems Software Ireland Limited, 4-6 Riverwalk,

Citywest Business Campus, Dublin 24, Republic of Ireland.

Omniture sets a cookie on the information technology system of the data subject. The

concept of a cookie has already been explained above. The controller ensures through a

server setting that the tracking data records transmitted to Adobe's data centre are

anonymised before geolocation. Anonymisation is implemented by replacing the last part

of the IP address. The controller has made settings on the server side to anonymise the IP

address of the data subject independently before any processing for geolocation and reach

measurement. Adobe will use the data and information obtained via our website on behalf

of the data controller to analyse the user behaviour of the data subject. Furthermore,

Adobe will use the data to create reports on user activity on our behalf and to provide

other services for our company in connection with the use of our website. The IP address of

the data subject will not be merged with other personal data by Adobe.

The data subject can prevent the setting of cookies by our website, as already described

above, at any time by means of an appropriate setting of the Internet browser used and

thus permanently object to the setting of cookies. Such a setting of the Internet browser

used would also prevent Omniture from setting a cookie on the information technology

system of the data subject. In addition, the cookies already set by Omniture can be deleted

at any time via an internet browser or other software programmes.

Furthermore, the data subject has the possibility to object to and prevent the collection of

data generated by the Adobe cookie and related to the use of this website as well as the

processing of this data by Adobe. To do so, the data subject must press the opt-out button

under the link www.adobe.com/de/privacy/opt-out.html, which sets an opt-out cookie. The

opt-out cookie set with the objection is stored on the information technology system used


12

by the data subject. If the cookies on the data subject's system are deleted after an

objection, the data subject must call up the link again and set a new opt-out cookie.

However, with the setting of the opt-out cookie, there is the possibility that the internet

pages of the controller are no longer fully usable for the data subject.

The applicable Adobe privacy policy can be found at www.adobe.com/de/privacy.html.

10.4. Privacy policy on the use and application of Adobe Stock Photos

The controller has integrated Adobe Stock Photos components on this website. Adobe

Stock is a service that gives designers and businesses access to millions of high-quality

curated and royalty-free photos, videos, illustrations, vector graphics, 3D assets and

templates for all their creative projects. Adobe Stock can be purchased as a multi-asset

subscription. Adobe Stock allows the embedding of stock images using an embed code, e.g.

text, video or image data provided by a third-party website.

The operating company is Adobe Systems Software Ireland Limited, 4-6 Riverwalk, Citywest

Business Campus, Dublin 24, Republic of Ireland.

Through the technical implementation of the embed code, the IP address of the user is

transmitted to Adobe Stock. Furthermore, Adobe Stock processes information about the

website, the browser type used, the browser language, the time and the length of the

access. In addition, Adobe Stock may collect information about the use of the website (e.g.

calling up sub-pages and clicking on links) as well as other interactions that users have

carried out when visiting the website. "Adobe Stock" also processes users' personal data in

the US and has submitted to the EU-US Privacy Shield.

When users register to use an Adobe website or application, create an Adobe ID, or contact

Adobe for assistance or to learn about other offerings, Adobe collects identifying

information. This includes, in particular, name, date of birth, company, email address and

country. In order to keep Adobe's databases up-to-date and to provide users with relevant

content and experiences, Adobe may combine information provided with data from third

party sources in accordance with applicable law. For example, the size, industry, and other

information about the company for which users work is determined from sources such as

business networking websites and information service providers. Adobe may also collect

and obtain information from third parties, including partners, and from publicly available

sources in order to detect, prevent, or otherwise manage fraud and security or technical

issues, and to prevent harm to the rights, property, or safety of Adobe and Adobe

employees, Adobe users, children, or the public.

Adobe collects information about how users use Adobe's apps and websites, including

when users use a desktop app feature that connects online (such as a photo sync feature).

Depending on the app or website, this information may be associated with the device or

browser or an Adobe account.

Adobe shares users' personal information with other third party data controllers. The third

parties to whom the information may be shared include: other Adobe - business groups,

Adobe's resellers and other distribution and advertising partners, retailers, research

organisations, advertisers, advertising agencies, advertising networks and platforms,

information services, fraud monitoring and prevention service providers, publishers, and

non-profit organisations. Adobe discloses personal information to companies,

organizations, or individuals outside of Adobe when Adobe believes in good faith that


13

access, use, preservation, or disclosure of the information is necessary to detect, prevent,

or otherwise address fraud, security-related, or technical issues and to protect the rights,

property, or safety of Adobe, Adobe employees, Adobe users, children, or the public as

required or permitted by law.

Users' personal information and files are stored on servers operated by Adobe and other

companies that provide services to Adobe. Adobe processes personal information primarily

in the United States and India. However, Adobe also transfers personal information to any

other country in the world where Adobe's applications and other products or services are

available. Adobe makes these transfers in compliance with applicable laws, for example, by

entering into data transfer agreements to protect personal information.

If users reside outside North America, Adobe Ireland is the contracting party. If Adobe

Ireland transfers your personal information to a country that is not in the EEA and is not

subject to an EU Commission adequacy decision, Adobe will rely on one or more of the

following legal mechanisms: standard contractual clauses approved by the European

Commission and/or your consent in certain circumstances. A copy of the relevant

mechanism is available for inspection upon request.

In some jurisdictions, users may have the right under the law to request that Adobe provide

them with a copy of their personal information, correct, erase, or restrict (stop) any (active)

processing of personal information, or transfer (port) the personal information that they

have provided to Adobe for a contract or with their consent in a structured, machine-

readable format to another data controller. In addition, users may object to the processing

of their personal information in certain circumstances (for example, if Adobe uses the data

for direct marketing). These rights may be limited, for example, if fulfilling the request

would disclose personal information of another person or if users request Adobe to delete

information that Adobe is required by law to retain or that is needed to defend claims

against Adobe. To exercise any of these rights (including deactivating your Adobe ID

account), users may contact Adobe directly or Adobe's Privacy Officer.

When users register for an account and create an Adobe ID, Adobe processes and retains

most of the personal information Adobe holds about users for as long as users are active

users of Adobe's products, services, or applications. When users close the account, Adobe

begins deleting certain personal information that it no longer has a business reason to

retain, such as the hash password or token-protected payment account data. However,

personal information related to Adobe's contract and business transactions with users is

usually retained by Adobe for a period of ten years after the last interaction with Adobe.

The applicable privacy policy can be found

athttps://www.adobe.com/de/privacy/policy.html.

10.5. Privacy policy on the use and application of affilinet

The controller has integrated components of the company affilinet on this website. Affilinet

is a German affiliate network that offers affiliate marketing.

Affiliate marketing is an Internet-supported form of distribution that enables commercial

operators of Internet sites, the so-called merchants or advertisers, to display advertising,

which is usually remunerated via click or sale commissions, on Internet sites of third

parties, i.e. distribution partners, who are also called affiliates or publishers. The merchant

provides an advertising medium via the affiliate network, i.e. an advertising banner or other

suitable means of Internet advertising, which is subsequently integrated by an affiliate on


14

its own Internet pages or advertised via other channels, such as keyword advertising or e-

mail marketing.

The operating company of Affilinet is affilinet GmbH, Sapporobogen 6-8, 80637 Munich,

Germany.

Affilinet sets a cookie on the information technology system of the data subject. What

cookies are has already been explained above. The Affilinet tracking cookie does not store

any personal data. Only the identification number of the affiliate, i.e. the partner referring

the potential customer, as well as the order number of the visitor to a website and the

advertising material clicked on are stored. The purpose of storing this data is to process

commission payments between a merchant and the affiliate, which are processed via the

affiliate network, i.e. Affilinet.

The data subject can prevent the setting of cookies by our website, as already described

above, at any time by means of an appropriate setting of the Internet browser used and

thus permanently object to the setting of cookies. Such a setting of the Internet browser

used would also prevent Affilinet from setting a cookie on the information technology

system of the data subject. In addition, cookies already set by Affilinet can be deleted at

any time via an internet browser or other software programs.

Affilinet's applicable privacy policy can be found at

www.affili.net/de/footeritem/datenschutz.

10.6. Privacy policy on the use and application of Coachy

The controller has integrated components of Coachy on this website.

The operating company is Coachy International Ltd, 36, St. Domenica Street, Victoria VCT

9030, Malta.

Coachy provides online video courses, landing pages, form templates for orders, imprint

and data protection, statistics, tests, exams, certificates, certificates and videos for

payment processing. In addition, Coachy provides the services for the collection of

newsletter prospects and the organisation and analysis of newsletter distribution. If you

enter data for the purpose of receiving the newsletter (e.g. name and email address), this

data is stored on Coachy's servers. These are the IP address used, time, duration of the

visit, browser type and, if applicable, the page of origin. This usage data is not linked to

your other personal data. The data provided in connection with the registration and use of

our pages and online video courses, such as in particular your name, e-mail address,

address and payment data, are stored on Coachy's servers. The processing of your personal

data takes place exclusively within the EU, unless otherwise stated below.

With the help of Coachy, we can analyse our newsletter campaigns. When you open an

email sent with Coachy, a file contained in the email connects to Coachy's servers. This

makes it possible to determine whether a newsletter message has been opened and which

links have been clicked on. Technical information is also collected. These cannot be

assigned to the respective newsletter recipient. It is used exclusively for the statistical

analysis of newsletter campaigns.

If you do not want any analysis by Coachy, you must unsubscribe from the newsletter. For

this purpose, we provide a corresponding link in each newsletter message or you can also

unsubscribe directly on the website.


15

Personal data will only be processed if consent has been given in advance (Art. 6 para. 1 lit.

a DSGVO). You can revoke this consent at any time by unsubscribing from the newsletter.

The legality of the data processing operations already carried out remains unaffected by

the revocation.

After the end of the purpose for which the data was collected, the duration of the storage

of the personal data is only as long as this is required on the basis of the statutory

provisions.

Coachy uses this data to provide and process payments for the online video courses and to

send newsletters on our behalf. In addition, the Provider uses them to optimise or improve

its own services, such as for the technical optimisation of the services. According to our

information, Coachy does not use this personal data to pass it on to third parties.

To operate the website, Coachy uses cookies or server-side sessions with your express

consent. Data can be stored in these.

You can currently find more information here: https://www.coachy.net/de/datenschutz/.

10.7. Privacy policy on the use and application of Facebook

The controller has integrated components of the company Facebook on this website.

Facebook is a social network.

A social network is a social meeting place operated on the Internet, an online community

that usually allows users to communicate and interact with each other in virtual space. A

social network can serve as a platform for exchanging opinions and experiences or enables

the internet community to provide personal or company-related information. Facebook

allows social network users to create private profiles, upload photos and network via friend

requests, among other things.

The operating company of Facebook is Facebook, Inc., 1 Hacker Way, Menlo Park, CA

94025, USA. The controller of personal data where a data subject lives outside the USA or

Canada is Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2,

Ireland.

Each time one of the individual pages of this website operated by the controller is called up

and on which a Facebook component (Facebook plug-in) has been integrated, the internet

browser on the information technology system of the data subject is automatically caused

by the respective Facebook component to download a representation of the corresponding

Facebook component from Facebook. A complete overview of all Facebook plug-ins can be

found at developers.facebook.com/docs/plugins/?locale=en_DE. Within the scope of this

technical procedure, Facebook receives information about which specific sub-page of our

website is visited by the data subject.

If the data subject is logged in to Facebook at the same time, Facebook recognises which

specific sub-page of our website the data subject is visiting each time the data subject calls

up our website and for the entire duration of the respective stay on our website. This

information is collected by the Facebook component and assigned by Facebook to the

respective Facebook account of the data subject. If the data subject activates one of the

Facebook buttons integrated on our website, for example the "Like" button, or if the data

subject posts a comment, Facebook assigns this information to the personal Facebook user

account of the data subject and stores this personal data.


16

Facebook always receives information via the Facebook component that the data subject

has visited our website if the data subject is logged into Facebook at the same time as

calling up our website; this takes place regardless of whether the data subject clicks on the

Facebook component or not. If the data subject does not want this information to be

transmitted to Facebook, he or she can prevent the transmission by logging out of his or

her Facebook account before accessing our website.

The data policy published by Facebook, which can be accessed at

en.facebook.com/about/privacy/, provides information on the collection, processing and

use of personal data by Facebook. It also explains which setting options Facebook offers to

protect the privacy of the data subject. In addition, various applications are available that

make it possible to suppress data transmission to Facebook. Such applications can be used

by the data subject to suppress data transmission to Facebook.

10.8. Privacy policy on the use and application of Facebook Pixel

The controller has integrated components of the Facebook Pixel company from Facebook

on this website. The Facebook pixel is a snippet of JavaScript code that loads a collection of

functions that allow Facebook to track your user actions if you have come to the user's

website via Facebook ads.

The operating company of Facebook Pixel is Facebook Ireland Limited, 4 Grand Canal

Square, Dublin 2, Ireland.

Each time one of the individual pages of this website operated by the controller is called up

and on which a Facebook component (Facebook plug-in) has been integrated, the internet

browser on the information technology system of the data subject is automatically caused

by the respective Facebook component to download a representation of the corresponding

Facebook component from Facebook. A complete overview of all Facebook plug-ins can be

found at developers.facebook.com/docs/plugins/?locale=en_DE. Within the scope of this

technical procedure, Facebook receives information about which specific sub-page of our

website is visited by the data subject.

If the data subject is logged into Facebook at the same time, Facebook recognises which

specific sub-page of our website the data subject is visiting each time the data subject calls

up our website and for the entire duration of the respective stay on our website. This

information is collected by the Facebook component and assigned by Facebook to the

respective Facebook account of the data subject. If the data subject activates one of the

Facebook buttons integrated on our website, for example the "Like" button, or if the data

subject posts a comment, Facebook assigns this information to the personal Facebook user

account of the data subject and stores this personal data.

Facebook always receives information via the Facebook component that the data subject

has visited our website if the data subject is logged into Facebook at the same time as

calling up our website; this takes place regardless of whether the data subject clicks on the

Facebook component or not. If the data subject does not want this information to be

transmitted to Facebook, he or she can prevent the transmission by logging out of his or

her Facebook account before accessing our website.

With the help of Facebook pixels, the advertising measures of the users can be better

adapted to their wishes and interests. In this way, Facebook users (provided they have

allowed personalised advertising) see suitable advertising. Furthermore, Facebook uses the

collected data for analysis purposes and its own advertisements.


17

The data policy published by Facebook, which can be accessed at

en.facebook.com/about/privacy/, provides information on the collection, processing and

use of personal data by Facebook. It also explains which setting options Facebook offers to

protect the privacy of the data subject. In addition, various applications are available that

make it possible to suppress data transmission to Facebook. Such applications can be used

by the data subject to suppress data transmission to Facebook.

Further information regarding Facebook Pixel's privacy policy can be found at

en.facebook.com/business/gdpr.

10.9. Privacy policy on the use and application of Getty Images images

The controller has integrated components of the company Getty Images on this website.

Getty Images is an American stock photo agency. A stock agency is a company that offers

images and other visual material on the market. Picture agencies usually market

photographs, illustrations and film material. Through a stock agency, different customers,

especially website operators, editorial departments of print and TV media and advertising

agencies, license the images they use.

The operating company of the Getty Images components is Getty Images International, 1st

Floor, The Herbert Building, The Park, Carrickmines, Dublin 18, Ireland.

Getty Images allows the embedding (possibly free of charge) of stock images. Embedding is

the inclusion or integration of specific third-party content, for example text, video or image

data, which is provided by a third-party website and then appears on your own website. A

so-called embedding code is used for embedding. An embedding code is an HTML code that

is integrated into an Internet page by an Internet page operator. If an embedding code has

been integrated by an Internet site operator, the external content of the other Internet site

is displayed immediately by default as soon as an Internet site is visited. To display the

external content, the external content is loaded directly from the other website. Getty

Images provides further information on embedding content under the link

www.gettyimages.de/resources/embed.

Through the technical implementation of the embedding code that enables the display of

images from Getty Images, the IP address of the internet connection through which the

data subject accesses our website is transmitted to Getty Images. Furthermore, Getty

Images records our website, the browser type used, the browser language, the time and

the length of the access. In addition, Getty Images may collect navigational information, i.e.

information about which of our sub-pages the data subject visited and which links were

clicked on, as well as other interactions the data subject carried out when visiting our

website. This data may be stored and analysed by Getty Images.

Further information and the applicable privacy policy of Getty Images can be found at

www.gettyimages.de/company/privacy-policy.

10.10. Privacy policy on the use and application of Google AdSense

The controller has integrated Google AdSense on this website. Google AdSense is an online

service that enables the placement of advertisements on third-party sites. Google AdSense

is based on an algorithm which selects the advertisements displayed on third party sites

according to the content of the respective third party site. Google AdSense allows interest-

related targeting of the Internet user, which is implemented by generating individual user

profiles.


18

The operating company of the Google AdSense component is Alphabet Inc., 1600

Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

The purpose of the Google AdSense component is the integration of advertisements on our

website. Google-AdSense sets a cookie on the information technology system of the data

subject. What cookies are has already been explained above. By setting the cookie,

Alphabet Inc. is enabled to analyse the use of our website. Each time one of the individual

pages of this website operated by the data controller is called up, on which a Google

AdSense component has been integrated, the internet browser on the data subject's

information technology system is automatically caused by the respective Google AdSense

component to transmit data to Alphabet Inc. for the purpose of online advertising and the

invoicing of commissions. In the course of this technical procedure, Alphabet Inc. obtains

knowledge of personal data, such as the IP address of the data subject, which Alphabet Inc.

uses, among other things, to trace the origin of visitors and clicks and subsequently to

enable commission settlements.

The data subject can prevent the setting of cookies by our website, as already described

above, at any time by means of an appropriate setting of the Internet browser used and

thus permanently object to the setting of cookies. Such a setting of the Internet browser

used would also prevent Alphabet Inc. from setting a cookie on the information technology

system of the data subject. In addition, a cookie already set by Alphabet Inc. can be deleted

at any time via the internet browser or other software programmes.

Google AdSense also uses so-called tracking pixels. A tracking pixel is a miniature graphic

that is embedded in web pages to enable log file recording and log file analysis, whereby a

statistical evaluation can be carried out. Based on the embedded tracking pixel, Alphabet

Inc. may see if and when a website was opened by a data subject, and which links were

clicked by the data subject. Among other things, tracking pixels are used to evaluate the

flow of visitors to a website.

Via Google AdSense, personal data and information, which also includes the IP address and

is necessary for the collection and billing of the advertisements displayed, are transferred

to Alphabet Inc. in the United States of America. This personal data is stored and processed

in the United States of America. Alphabet Inc. may share this personal data collected via

the technical process with third parties.

Google-AdSense is explained in more detail under this link

www.google.de/intl/de/adsense/start/.

10.11. Privacy policy on the use and application of Google AdWords

The controller has integrated Google AdWords on this website. Google AdWords is an

internet advertising service that allows advertisers to place ads both in Google's search

engine results and in the Google advertising network. Google AdWords allows an advertiser

to specify certain keywords in advance, by means of which an ad is displayed in Google's

search engine results exclusively when the user retrieves a keyword-relevant search result

with the search engine. In the Google advertising network, the ads are distributed on topic-

relevant websites by means of an automatic algorithm and taking into account the

previously defined keywords.

The operating company of the Google AdWords services is Google Inc., 1600 Amphitheatre

Pkwy, Mountain View, CA 94043-1351, USA.


19

The purpose of Google AdWords is to advertise our website by displaying interest-relevant

advertising on the websites of third-party companies and in the search engine results of the

Google search engine and to display third-party advertising on our website.

If a data subject accesses our website via a Google ad, a so-called conversion cookie is

stored by Google on the data subject's information technology system. What cookies are

has already been explained above. A conversion cookie loses its validity after 30 days and

does not serve to identify the data subject. If the cookie has not yet expired, the conversion

cookie is used to track whether certain sub-pages, for example the shopping basket of an

online shop system, have been called up on our website. The conversion cookie enables

both us and Google to track whether a data subject who has accessed our website via an

AdWords ad has generated a sale, i.e. has completed or cancelled a purchase of goods.

The data and information collected through the use of the conversion cookie are used by

Google to create visit statistics for our website. These visit statistics are in turn used by us

to determine the total number of users who were referred to us via AdWords ads, i.e. to

determine the success or failure of the respective AdWords ad and to optimise our

AdWords ads for the future. Neither our company nor other advertisers of Google AdWords

receive information from Google by means of which the data subject could be identified.

By means of the conversion cookie, personal information, such as the websites visited by

the data subject, is stored. Each time the data subject visits our website, personal data,

including the IP address of the internet connection used by the data subject, is transmitted

to Google in the United States of America. This personal data is stored by Google in the

United States of America. Google may pass on this personal data collected via the technical

procedure to third parties.

The data subject can prevent the setting of cookies by our website, as already described

above, at any time by means of an appropriate setting of the internet browser used and

thus permanently object to the setting of cookies. Such a setting of the internet browser

used would also prevent Google from setting a conversion cookie on the information

technology system of the data subject. In addition, a cookie already set by Google AdWords

can be deleted at any time via the internet browser or other software programmes.

Furthermore, the data subject has the option to object to interest-based advertising by

Google. To do this, the data subject must call up the link www.google.de/settings/ads from

any of the internet browsers he or she uses and make the desired settings there.

Further information and Google's applicable privacy policy can be found at

www.google.de/intl/de/policies/privacy/.

10.12. Privacy policy on the use and application of Google Drive

The controller has integrated Google Drive on this website. Google Drive is a file hosting

online service that allows you to store, share and edit documents in the cloud. Google Drive

includes Google Docs, Sheets, Slides and Forms.

The purpose of Google Drive is the direct editing of text documents, spreadsheets,

presentations.

The operating company of the Google Drive component is Alphabet Inc, 1600 Amphitheatre

Pkwy, Mountain View, CA 94043-1351, USA.


20

A cookie is a short text snippet that is sent to your browser from a website you visit. This

stores information about your last visit.

By means of the cookie, personal information, for example the access time, the location

from which an access originated and the frequency of visits to our website by the data

subject, is stored. Each time the data subject visits our website, this personal data,

including the IP address of the internet connection used by the data subject, is transmitted

to Google in the United States of America. This personal data is stored by Google in the

United States of America. Google may pass on this personal data collected via the technical

process to third parties.

The data subject can prevent the setting of cookies by our website, as already described

above, at any time by means of an appropriate setting of the Internet browser used and

thus permanently object to the setting of cookies. Such a setting of the Internet browser

used would also prevent Alphabet Inc. from setting a cookie on the information technology

system of the data subject. In addition, a cookie already set by Alphabet Inc. can be deleted

at any time via the internet browser or other software programmes.

Google Drive is explained in more detail at this link https://www.google.com/intl/de/drive/.

Further information and Google's applicable privacy policy can be found at

www.google.de/intl/de/policies/privacy/ and at www.google.com/analytics/terms/de.html.

10.13. Privacy policy on the use and application of Google+

The controller has integrated the Google+ button as a component on this website. Google+

is a so-called social network. A social network is a social meeting place operated on the

Internet, an online community, which usually enables users to communicate and interact

with each other in virtual space. A social network can serve as a platform for sharing

opinions and experiences or enables the internet community to provide personal or

company-related information. Google+ allows users of the social network to create private

profiles, upload photos and network via friend requests, among other things.

The operating company of Google+ is Google Inc., 1600 Amphitheatre Pkwy, Mountain

View, CA 94043-1351, USA.

Each time one of the individual pages of this website operated by the data controller is

called up and on which a Google+ button has been integrated, the internet browser on the

data subject's information technology system is automatically caused by the respective

Google+ button to download a representation of the corresponding Google+ button from

Google. Within the scope of this technical procedure, Google receives information about

which specific sub-page of our website is visited by the data subject. More detailed

information on Google+ is available at developers.google.com/+/.

If the data subject is logged into Google+ at the same time, Google recognises which

specific sub-page of our website the data subject is visiting each time the data subject calls

up our website and for the entire duration of the respective stay on our website. This

information is collected by the Google+ button and assigned by Google to the respective

Google+ account of the data subject.

If the data subject activates one of the Google+ buttons integrated on our website and thus

makes a Google+1 recommendation, Google will associate this information with the data

subject's personal Google+ user account and store this personal data. Google stores the


21

Google+1 recommendation of the data subject and makes it publicly available in

accordance with the terms and conditions accepted by the data subject in this regard. A

Google+1 recommendation made by the data subject on this website will subsequently be

stored and processed together with other personal data, such as the name of the Google+1

account used by the data subject and the photo stored in this account, in other Google

services, for example the search engine results of the Google search engine, the Google

account of the data subject or in other places, for example on websites or in connection

with advertisements. Furthermore, Google is able to link the visit to this website with other

personal data stored by Google. Google also records this personal information for the

purpose of improving or optimising Google's various services.

Google always receives information via the Google+ button that the data subject has visited

our website if the data subject is simultaneously logged into Google+ at the time of calling

up our website; this takes place regardless of whether the data subject clicks on the

Google+ button or not.

If the data subject does not want personal data to be transmitted to Google, he or she can

prevent such transmission by logging out of his or her Google+ account before accessing

our website.

Further information and the applicable Google privacy policy can be found at

www.google.de/intl/de/policies/privacy/. Further guidance from Google on the Google+1

button can be found at developers.google.com/+/web/buttons-policy.

10.14. Privacy policy on the use and application of Hyros

The controller has integrated Hyros components on this website.

The operating company of the Hyros component is Hyros, Inc, 13359 N Highway 183 Ste

406 # 2008, Austin, TX 78750 US.

The purpose of Hyros is what is known as ad tracking. Ad tracking is the collection of data

and insights about online advertising campaigns. This personal data is used to show you

personalised and targeted content. In addition, your data is used for internal production

development purposes to develop new products and services and to improve existing ones.

Hyros uses cookies. The use of cookies enables an analysis of the use of our website. By

means of the cookie, personal information, such as the access time, the place from which

an access originated and the frequency of visits to our website by the data subject, is

stored. Each time a data subject accesses one of the individual pages of this website

operated by the data controller on which a Hyros component has been integrated, the

Internet browser on the data subject's information technology system is automatically

triggered by the respective Hyros component to transmit data to Hyros for the purpose of

online analysis. This personal data is stored by Hyros in the United States of America. Hyros

may pass on this personal data collected via the technical procedure to third parties.

The data subject can prevent the setting of cookies by our website, as already described

above, at any time by means of an appropriate setting of the Internet browser used and

thus permanently object to the setting of cookies. In addition, a cookie already set by Hyros

can be deleted at any time via the Internet browser or other software programs.


22

Personal data will only be processed if consent has been given beforehand (Art. 6 para. 1 lit.

a DSGVO). You can revoke this consent at any time. The legality of the data processing

operations already carried out remains unaffected by the revocation.

After the end of the purpose for which the data was collected, the duration of the storage

of the personal data is only as long as this is required on the basis of the statutory

provisions.

Further information and Hyros' applicable privacy policy can be found at

https://hyros.com/terms-and-conditions.html and at https://hyros.com/privacy.html.

Hyros is also explained in more detail at this link https://hyros.com/.

10.15. Privacy policy on the use and application of Instagram

The controller has integrated components of the Instagram service on this website.

Instagram is a service that qualifies as an audiovisual platform and allows users to share

photos and videos and also to redistribute such data on other social networks.

The operating company of the Instagram services is Instagram LLC, 1 Hacker Way, Building

14 First Floor, Menlo Park, CA, USA.

Each time one of the individual pages of this website operated by the data controller is

called up and on which an Instagram component (Insta button) has been integrated, the

internet browser on the information technology system of the data subject is automatically

caused by the respective Instagram component to download a representation of the

corresponding component from Instagram. Within the scope of this technical procedure,

Instagram receives knowledge about which specific subpage of our website is visited by the

data subject.

If the data subject is logged in to Instagram at the same time, Instagram recognises which

specific subpage the data subject is visiting each time the data subject calls up our website

and for the entire duration of the respective stay on our website. This information is

collected by the Instagram component and assigned by Instagram to the respective

Instagram account of the data subject. If the data subject activates one of the Instagram

buttons integrated on our website, the data and information thus transmitted will be

assigned to the personal Instagram user account of the data subject and stored and

processed by Instagram.

Instagram always receives information via the Instagram component that the data subject

has visited our website if the data subject is logged into Instagram at the same time as

calling up our website; this takes place regardless of whether the data subject clicks on the

Instagram component or not. If the data subject does not want this information to be

transmitted to Instagram, he or she can prevent the transmission by logging out of his or

her Instagram account before accessing our website.

More information and Instagram's applicable privacy policy can be found at

help.instagram.com/155833707900388 and www.instagram.com/about/legal/privacy/.

10.16. Privacy policy on the use and application of KlickTipp

The controller has integrated components of KlickTipp on this website. KlickTipp is a UK-

based marketing automation platform and email marketing service.


23

The operating company is KLICK-TIPP LIMITED, Representatives: Michael Toohig, Josef

Wolosz, 15 Cambridge Court, 210 Shepherd's Bush Road, London W6 7NJ, United Kingdom.

Information on the exact scope of services can be found at

https://www.klicktipp.com/features/.

10.17. Privacy policy on the use and application of LinkedIn

The controller has integrated components of the LinkedIn Corporation on this website.

LinkedIn is an internet-based social network that allows users to connect with existing

business contacts and to make new business contacts. Over 400 million registered people

use LinkedIn in more than 200 countries. This makes LinkedIn currently the largest platform

for business contacts and one of the most visited websites in the world.

The operating company of LinkedIn is LinkedIn Corporation, 2029 Stierlin Court Mountain

View, CA 94043, USA. For data protection issues outside the USA, LinkedIn Ireland, Privacy

Policy Issues, Wilton Plaza, Wilton Place, Dublin 2, Ireland, is responsible.

With each individual call-up of our website that is equipped with a LinkedIn component

(LinkedIn plug-in), this component causes the browser used by the person concerned to

download a corresponding representation of the component from LinkedIn. Further

information on LinkedIn plug-ins can be found at developer.linkedin.com/plugins. As part of

this technical procedure, LinkedIn receives information about which specific subpage of our

website is visited by the data subject.

If the data subject is logged in to LinkedIn at the same time, LinkedIn recognises which

specific subpage of our website the data subject is visiting with each call-up of our website

by the data subject and for the entire duration of the respective stay on our website. This

information is collected by the LinkedIn component and assigned by LinkedIn to the

respective LinkedIn account of the data subject. If the data subject activates a LinkedIn

button integrated on our website, LinkedIn assigns this information to the personal

LinkedIn user account of the data subject and stores this personal data.

LinkedIn always receives information via the LinkedIn component that the data subject has

visited our website if the data subject is logged into LinkedIn at the same time as calling up

our website; this takes place regardless of whether the data subject clicks on the LinkedIn

component or not. If the data subject does not want this information to be transmitted to

LinkedIn, he or she can prevent the transmission by logging out of his or her LinkedIn

account before accessing our website.

LinkedIn offers the ability to unsubscribe from email messages, SMS messages and targeted

ads, as well as manage ad settings at www.linkedin.com/psettings/guest-controls. LinkedIn

also uses partners such as Quantcast, Google Analytics, BlueKai, DoubleClick, Nielsen,

Comscore, Eloqua and Lotame, which may set cookies. Such cookies can be rejected at

www.linkedin.com/legal/cookie-policy. LinkedIn's applicable privacy policy is available at

www.linkedin.com/legal/privacy-policy. LinkedIn's cookie policy is available at

www.linkedin.com/legal/cookie-policy.

10.18. Privacy policy on the use and application of Outlook as a web hosting programme

The controller has integrated components of Outlook on this website as part of web

hosting. Web hosting is the provision of web space and the hosting of websites on the web

server of an Internet service provider.


24

Microsoft Outlook is a widely used software from Microsoft for receiving and sending e-

mails and for managing appointments, contacts, tasks and notes.

The operating company is Microsoft Corporation, One Microsoft Way, Redmond, WA

98052-6399, USA.

Microsoft collects data about users, through interactions with users, and about products.

Some of this data is provided by users directly, and some is obtained by Microsoft through

the collection of information about activities, usage and experiences with Microsoft

products. The data collected depends on the context of users' interactions with Microsoft

and users' preferences, including privacy settings and the products and features users use.

We also receive data about users from third parties. Microsoft is also required by law to

collect personal information when users and Microsoft sign or enter into a contract. If users

do not want to provide data, Microsoft cannot enter into a contract with users.

Microsoft uses the data to provide users with rich, interactive user experiences. In

particular, Microsoft wants to provide products, including updating, backup,

troubleshooting and support. This includes sharing data when necessary to provide the

service or complete the transactions that users have requested. Further, Microsoft collects

the data to, among other things, develop and improve products.

Microsoft combines data collected from different contexts (e.g., from the use of two

Microsoft products) or from third parties to provide users with a seamless, consistent, and

personalised experience in order to make informed decisions or use it for other legitimate

purposes. Processing of personal data for these purposes includes both automated and

manual (human) processing methods.

Microsoft shares users' personal information with their consent or to complete a

transaction or offer a product that users have requested or authorised. Microsoft Outlook

also shares data with Microsoft-controlled affiliates and with suppliers who do work for

Microsoft. Users also have choices about how Microsoft collects and uses their information.

Users can control their personal information that Microsoft has acquired and exercise

privacy rights by contacting Microsoft or using various tools that Microsoft provides.

Microsoft uses cookies and similar technologies to store and maintain user preferences and

settings.

The applicable privacy policy of Microsoft Outlook, operated by Microsoft, can be found at

privacy.microsoft.com/en/privacystatement and privacy.microsoft.com/en/.

10.19. Privacy policy on the use and application of PayPal as a payment method

The controller has integrated components of PayPal on this website. PayPal is an online

payment service provider. Payments are processed via so-called PayPal accounts, which

represent virtual private or business accounts. In addition, PayPal offers the possibility of

processing virtual payments via credit cards if a user does not have a PayPal account. A

PayPal account is managed via an e-mail address, which is why there is no classic account

number. PayPal makes it possible to initiate online payments to third parties or to receive

payments. PayPal also assumes trustee functions and offers buyer protection services.

The European operating company of PayPal is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24

Boulevard Royal, 2449 Luxembourg, Luxembourg.


25

If the data subject selects "PayPal" as a payment option during the ordering process in our

online shop, data of the data subject will be automatically transmitted to PayPal. By

selecting this payment option, the data subject consents to the transmission of personal

data required for payment processing.

The personal data transmitted to PayPal are usually first name, last name, address, email

address, IP address, telephone number, mobile phone number or other data that are

necessary for the processing of the payment. Personal data that is necessary for the

processing of the purchase contract is also personal data that is related to the respective

order.

The purpose of the transfer of data is payment processing and fraud prevention. The

controller will transfer personal data to PayPal in particular if there is a legitimate interest

for the transfer. The personal data exchanged between PayPal and the controller may be

transferred by PayPal to credit reference agencies. The purpose of this transmission is to

check identity and creditworthiness.

PayPal may share personal data with affiliated companies and service providers or

subcontractors to the extent necessary to fulfil its contractual obligations or to process the

data on its behalf.

The data subject has the option to revoke the consent to the handling of personal data at

any time vis-à-vis PayPal. A revocation does not affect personal data that must be

processed, used or transmitted for (contractual) payment processing.

PayPal's applicable privacy policy can be found at

www.paypal.com/de/webapps/mpp/ua/privacy-full.

10.20. Privacy policy on the use and application of PayPal Plus as a payment method

The controller has integrated Paypal Plus components on this website. Paypal Plus serves as

the payment method. If you decide to pay with the online payment service provider PayPal

during your order process, your contact details will be transmitted to PayPal as part of the

order triggered in this way. PayPal assumes the function of an online payment service

provider as well as a trustee and offers buyer protection services.

The operating company of PayPal is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard

Royal, L-2449 Luxembourg.

The personal data transmitted to PayPal is mostly first name, last name, address, telephone

number, IP address, email address, or other data required for order processing, as well as

data related to the order, such as number of items, item number, invoice amount and tax

percentage, billing information, etc.

This transmission is necessary for the processing of your order with the payment method

selected by you, in particular for the confirmation of your identity, the administration of

your payment and the customer relationship. However, please note: Personal data may

also be passed on by PayPals to service providers, subcontractors or other affiliated

companies, insofar as this is necessary to fulfil the contractual obligations arising from your

order or the personal data is to be processed on behalf of PayPals.

Depending on the payment method selected via PayPal, e.g. invoice or direct debit, the

personal data transmitted to PayPal will be transferred by PayPal to credit agencies. This


26

transmission serves to check your identity and creditworthiness in relation to the order you

have placed.

Further information regarding the applicable data protection provisions of Paypal Plus can

be found at www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE.

10.21. Privacy policy on the use and application of Twitter

The controller has integrated Twitter components on this website. Twitter is a multilingual

publicly accessible microblogging service on which users can publish and distribute so-

called tweets, i.e. short messages limited to 280 characters. These short messages can be

accessed by anyone, including people who are not registered with Twitter. However, the

tweets are also displayed to the so-called followers of the respective user. Followers are

other Twitter users who follow the tweets of a user. Furthermore, Twitter makes it possible

to address a broad audience via hashtags, links or retweets.

The operating company of Twitter is Twitter, Inc., 1355 Market Street, Suite 900, San

Francisco, CA 94103, USA.

Each time one of the individual pages of this website operated by the controller is called up

and on which a Twitter component (Twitter button) has been integrated, the internet

browser on the information technology system of the data subject is automatically caused

by the respective Twitter component to download a representation of the corresponding

Twitter component from Twitter. Further information on the Twitter buttons can be found

at about.twitter.com/en/resources/buttons. Within the scope of this technical procedure,

Twitter receives information about which specific sub-page of our website is visited by the

data subject. The purpose of integrating the Twitter component is to enable our users to

disseminate the content of this website, to make this website known in the digital world

and to increase our visitor numbers.

If the data subject is logged into Twitter at the same time, Twitter recognises which specific

sub-page of our website the data subject is visiting each time the data subject calls up our

website and for the entire duration of the respective stay on our website. This information

is collected by the Twitter component and assigned by Twitter to the respective Twitter

account of the data subject. If the data subject activates one of the Twitter buttons

integrated on our website, the data and information thus transmitted will be assigned to

the personal Twitter user account of the data subject and stored and processed by Twitter.

Twitter always receives information via the Twitter component that the data subject has

visited our website if the data subject is logged into Twitter at the same time as calling up

our website; this takes place regardless of whether the data subject clicks on the Twitter

component or not. If the data subject does not want this information to be transmitted to

Twitter, he or she can prevent the transmission by logging out of his or her Twitter account

before accessing our website.

Twitter's applicable privacy policy is available at twitter.com/privacy?lang=en.

10.22. Privacy policy on the use and application of web hosting via IONOS

The controller has integrated web hosting components via IONOS on this website. Web

hosting is the provision of web space and the hosting of websites on the web server of an

Internet Service Provider (ISP).


27

The operating company is 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany.

In the case of web hosting, inventory data, contact data, content data, contract data, usage

data, meta data and communication data of customers, interested parties and visitors of

this online offer are processed on the basis of our legitimate interests in an efficient and

secure provision of this online offer pursuant to Art. 6 (1) lit. f DSGVO in conjunction with

Art. 28 DSGVO. Art. 28 DSGVO. In some cases, Webhosting 1&1 uses external service

providers to process your data. These have been carefully selected and commissioned, are

bound by the instructions of IONOS and are regularly monitored.

Where service providers or partners are based in a country outside the European Economic

Area (EEA), IONOS will inform you of the consequences of this circumstance in the

description of the respective function.

For further information, please refer to the privacy policy of 1&1 IONOS SE at

hosting.1und1.de/terms-gtc/terms-privacy/.

10.23. Privacy policy on the use and application of Wistia

The controller has integrated components of the video portal Wistia on this website.

The operating company is Wistia Inc, 17 Tudor Street Cambridge, Massachusetts, 02139

USA.

When a page equipped with a Wistia plugin is visited, a connection to the Wistia servers is

established. This tells the Wistia server which of the pages was visited and when. In

addition, Wistia obtains the IP address. This also applies if the visitor is not logged in to

Wistia or does not have an account with Wistia. The information collected by Wistia is

transmitted to the Wistia server in the USA.

If the visitor is logged into his Wistia account, this enables Wistia to assign the surfing

behaviour directly to the visitor's personal profile. This can be prevented by the visitor

logging out of their Wistia account.

Further information on the collection and use of data by Wistia can be found in Wistia's

privacy policy: wistia.com/privacy

10.24. Privacy policy on the use and application of Wufoo

The controller has integrated components of Wufoo on this website. Wufoo is a form

service.

The operating company is Momentive Europe UC, 2 Shelbourne Buildings, Second Floor,

Shelbourne Rd Ballsbridge, Dublin 4,

Ireland

When using the contact forms, the email address, other contact data, details of your

professional position and details of your request are collected and processed. The data is

collected with the help of the form service Wufoo. This means that the content entered by

the user in a contact form is processed and stored. Depending on the respective contact

form, the content may include the following: Company, name, email address, telephone

number, preferred supplier, invoice number, credit card details, information on products as

well as other self-explanatory fields with individual queries. The content is not processed

and stored until you submit a form. H


28

The applicable data protection regulations can be found here:

https://www.wufoo.com/privacy/

10.25. Privacy policy on the use and application of Xing

The controller has integrated components of Xing on this website. Xing is an internet-based

social network that allows users to connect with existing business contacts and to make

new business contacts. Individual users can create a personal profile of themselves on Xing.

Companies can, for example, create company profiles or publish job offers on Xing.

The operating company of Xing is XING SE, Dammtorstraße 30, 20354 Hamburg, Germany.

Each time one of the individual pages of this website operated by the controller is called up

and on which a Xing component (Xing plug-in) has been integrated, the internet browser on

the information technology system of the data subject is automatically prompted by the

respective Xing component to download a representation of the corresponding Xing

component from Xing. Further information on the Xing plug-ins can be found at

dev.xing.com/plugins. Within the scope of this technical procedure, Xing receives

information about which specific sub-page of our website is visited by the data subject.

If the data subject is logged in to Xing at the same time, Xing recognises which specific

subpage of our website the data subject is visiting each time the data subject calls up our

website and for the entire duration of the respective stay on our website. This information

is collected by the Xing component and assigned by Xing to the respective Xing account of

the data subject. If the data subject activates one of the Xing buttons integrated on our

website, for example the "Share" button, Xing assigns this information to the personal Xing

user account of the data subject and stores this personal data.

Xing always receives information via the Xing component that the data subject has visited

our website if the data subject is logged into Xing at the same time as calling up our

website; this takes place regardless of whether the data subject clicks on the Xing

component or not. If the data subject does not want this information to be transmitted to

Xing, he or she can prevent the transmission by logging out of his or her Xing account

before accessing our website.

The data protection provisions published by Xing, which can be accessed at

www.xing.com/privacy, provide information on the collection, processing and use of

personal data by Xing. Furthermore, Xing has published data protection information for the

XING Share button at www.xing.com/app/share?op=data_protection.

10.26. Privacy policy on the use and application of YouTube

The controller has integrated YouTube components on this website. YouTube is an Internet

video portal that allows video publishers to post video clips free of charge and other users

to view, rate and comment on them, also free of charge. YouTube allows the publication of

all types of videos, which is why complete film and television programmes, but also music

videos, trailers or videos made by users themselves can be accessed via the Internet portal.

The operating company of YouTube is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066,

USA. YouTube, LLC is a subsidiary of Google Inc, 1600 Amphitheatre Pkwy, Mountain View,

CA 94043-1351, USA.


29

Each time one of the individual pages of this website operated by the data controller is

called up and on which a YouTube component (YouTube video) has been integrated, the

internet browser on the information technology system of the data subject is automatically

caused by the respective YouTube component to download a representation of the

corresponding YouTube component from YouTube. Further information on YouTube can be

found at www.youtube.com/yt/about/de/. Within the scope of this technical procedure,

YouTube and Google receive information about which specific sub-page of our website is

visited by the data subject.

If the data subject is logged into YouTube at the same time, YouTube recognises which

specific sub-page of our website the data subject is visiting when a sub-page containing a

YouTube video is called up. This information is collected by YouTube and Google and

assigned to the respective YouTube account of the data subject.

YouTube and Google always receive information via the YouTube component that the data

subject has visited our website if the data subject is logged into YouTube at the same time

as calling up our website; this takes place regardless of whether the data subject clicks on a

YouTube video or not. If the data subject does not want this information to be transmitted

to YouTube and Google, he or she can prevent the transmission by logging out of his or her

YouTube account before accessing our website.

The privacy policy published by YouTube, which can be accessed at

www.google.de/intl/de/policies/privacy/, provides information on the collection,

processing and use of personal data by YouTube and Google.

10.27. Privacy policy on the use and application of Zoom

The controller has integrated Zoom components on this website.

The operating company is Zoom Video Communications, Inc, 55 Almaden Blvd, Suite 600,

San Jose, CA 95113, USA.

Zoom collects the following information, among others, when users register for a free

Zoom account: Date of birth (only as proof of age), first and last name and telephone

numbers. For users who create a paid Zoom account, Zoom stores in particular user data in

connection with a Zoom account, telephone number for billing purposes and billing

address. Zoom automatically stores technical information from Zoom's software or systems

that host the services, as well as from systems, applications and devices used to access the

services, when the Zoom services are used. Location data, among other things, is also

automatically collected.

Zoom will share personal data with companies, organisations and individuals outside of

Zoom and third parties where personal consent has been obtained from users (if required).

Where Zoom has received personal data through a Zoom partner and the user becomes a

customer, Zoom may share selected personal data with the relevant partner or its agent

under the partner agreement in order to reward a referral partner of a co-sponsored event.

Zoom's partners have contractually agreed to comply with appropriate privacy and security

obligations. Zoom provides personal data to suppliers and service providers to assist Zoom

in providing the Services and for Zoom's business purposes.

If users wish to correct or update information you have provided to Zoom, users must

contact Zoom directly at www.zoom.us and update their profile. If users are located in the

European Economic Area, users may have the right to exercise certain data protection


30

rights available to them under applicable law. Zoom will process requests from these users

in accordance with applicable data protection laws. Zoom may need to retain certain

information for record-keeping purposes or to complete transactions that users have

initiated prior to the request for deletion.

Zoom operates globally, which means that personal data may be stored and processed in

any country where Zoom or its service providers have facilities or hold events. Zoom will

retain collected personal data for as long as necessary, unless a longer retention period is

required by law.

The applicable privacy policy can be found at zoom.us/en/privacy.html.

10.28. Legal basis of the processing

Article 6 I lit. a DS-GVO serves as the legal basis for our company for processing operations

in which we obtain consent for a specific processing purpose. If the processing of personal

data is necessary for the performance of a contract to which the data subject is a party, as

is the case, for example, with processing operations that are necessary for the delivery of

goods or the provision of any other service or consideration, the processing is based on

Article 6 I lit. b DS-GVO. The same applies to processing operations that are necessary for

the implementation of pre-contractual measures, for example in the case of enquiries

about our products or services. If our company is subject to a legal obligation by which the

processing of personal data becomes necessary, such as for the fulfilment of tax

obligations, the processing is based on Art. 6 I lit. c DS-GVO. In rare cases, the processing of

personal data might become necessary in order to protect the vital interests of the data

subject or another natural person. This would be the case, for example, if a visitor were to

be injured on our premises and as a result his or her name, age, health insurance details or

other vital information had to be passed on to a doctor, hospital or other third party. Then

the processing would be based on Art. 6 I lit. d DS-GVO. Finally, processing operations could

be based on Art. 6 I lit. f DS-GVO. Processing operations which are not covered by any of

the aforementioned legal bases are based on this legal basis if the processing is necessary

to protect a legitimate interest of our company or a third party, provided that the interests,

fundamental rights and freedoms of the data subject are not overridden. Such processing

operations are permitted to us in particular because they were specifically mentioned by

the European legislator. In this respect, it took the view that a legitimate interest could be

assumed if the data subject is a customer of the controller (recital 47, sentence 2 of the

GDPR).

10.29. Legitimate interests in the processing pursued by the controller or a third party

If the processing of personal data is based on Article 6 I lit. f DS-GVO, our legitimate interest

is the performance of our business activities for the benefit of the well-being of all our

employees and our shareholders.

10.30. Duration for which the personal data are stored

The criterion for the duration of the storage of personal data is the respective statutory

retention period. After expiry of the period, the corresponding data is routinely deleted if it

is no longer required for the fulfilment or initiation of the contract.

10.31. Legal or contractual requirements to provide the personal data; necessity for the

conclusion of the contract; obligation of the data subject to provide the personal data;

possible consequences of non-provision


31

We would like to inform you that the provision of personal data is sometimes required by

law (e.g. tax regulations) or may also result from contractual regulations (e.g. information

on the contractual partner). Sometimes, in order to conclude a contract, it may be

necessary for a data subject to provide us with personal data that must subsequently be

processed by us. For example, the data subject is obliged to provide us with personal data if

our company concludes a contract with him or her. Failure to provide the personal data

would mean that the contract with the data subject could not be concluded. Before

providing personal data by the data subject, the data subject must contact one of our

employees. Our employee will inform the data subject on a case-by-case basis whether the

provision of the personal data is required by law or contract or is necessary for the

conclusion of the contract, whether there is an obligation to provide the personal data and

what the consequences of not providing the personal data would be.

10.32. Existence of automated decision making

As a responsible company, we do not use automatic decision-making or profiling.

10.33. Creation of this privacy policy

This privacy policy was created by SYLVENSTEIN Rechtsanwälte in cooperation with DGD

Deutsche Gesellschaft für Datenschutz GmbH.

Your Cart

Your cart is empty

Browse products and add items to your cart