Privacy Policy

1) Introduction and Contact Details of the Data Controller

1.1 We are pleased that you visit our website and thank you for your interest. In the following, we inform you about the handling of your personal data when using our website. Personal data is any data that can be used to personally identify you.

1.2 The data controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Simon Daniel März, ProjectMakers, Steinweg 2, 34376 Immenhausen, Germany, Tel.: 01702912189, E-Mail: [email protected]. The data controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.

2) Data Collection When Visiting Our Website

2.1 When using our website purely for informational purposes, i.e., if you do not register or otherwise transmit information to us, we only collect data that your browser transmits to the page server (so-called "server log files"). When you access our website, we collect the following data that is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time at the time of access
  • Amount of data sent in bytes
  • Source/referrer from which you reached the page
  • Browser used
  • Operating system used
  • IP address used (possibly in anonymized form)

The processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. The data is not transferred or used for any other purpose. However, we reserve the right to retrospectively check the server log files should concrete indications of illegal use arise.

2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the data controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the character string "https://" and the lock symbol in your browser bar.

3) Hosting & Content Delivery Network

For hosting our website and displaying page content, we use a provider that provides its services either directly or through selected subcontractors exclusively on servers within the European Union.

All data collected on our website is processed on these servers.

We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

4) Cookies

To make visiting our website attractive and to enable the use of certain functions, we use cookies, i.e., small text files that are stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called "session cookies"), while others remain on your device longer and enable the storage of page settings (so-called "persistent cookies"). In the latter case, you can see the storage duration in the cookie settings overview of your web browser.

If personal data is also processed by individual cookies we use, the processing is carried out in accordance with Art. 6 Para. 1 lit. b GDPR either for the performance of the contract, in accordance with Art. 6 Para. 1 lit. a GDPR in the case of given consent, or in accordance with Art. 6 Para. 1 lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the page visit.

You can set your browser so that you are informed about the setting of cookies and decide individually about their acceptance or exclude the acceptance of cookies for certain cases or in general.

Please note that if cookies are not accepted, the functionality of our website may be limited.

5) Contact

5.1 Trustpilot

For review reminders, we use the services of the following provider: Trustpilot A/S, Pilestraede 58, 1112 Copenhagen, Denmark

Exclusively based on your explicit consent according to Art. 6 Para. 1 lit. a GDPR  we transmit your email address and possibly other customer data to the provider so that they can contact you with a review reminder by email.

You can withdraw your consent at any time with effect for the future from us or the provider.

We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

5.2 In the context of contacting us (e.g., via contact form or email), personal data is processed – exclusively for the purpose of processing and responding to your request and only to the extent necessary for this purpose.

The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Art. 6 Para. 1 lit. f GDPR. If your contact aims at concluding a contract, the additional legal basis for processing is Art. 6 Para. 1 lit. b GDPR. Your data will be deleted when it can be inferred from the circumstances that the matter in question has been conclusively clarified and provided no statutory retention obligations oppose this.

6) Data Processing When Opening a Customer Account

In accordance with Art. 6 Para. 1 lit. b GDPR, personal data continues to be collected and processed to the extent necessary if you provide it to us when opening a customer account. You can see which data is required for opening an account from the input mask of the corresponding form on our website.

Deletion of your customer account is possible at any time and can be done by sending a message to the above-mentioned address of the data controller. After deletion of your customer account, your data will be deleted provided that all contracts concluded through it have been fully processed, no statutory retention periods oppose this, and we have no legitimate interest in continued storage.

7) Use of Customer Data for Direct Marketing

Registration for our email newsletter

If you subscribe to our email newsletter, we regularly send you information about our offers. The mandatory information for sending the newsletter is your email address alone. Providing additional data is voluntary and is used to address you personally. For newsletter dispatch, we use the so-called double opt-in procedure, which ensures that you only receive newsletters after you have expressly confirmed your consent to receive newsletters by clicking on a verification link sent to the specified email address.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 Para. 1 lit. a GDPR. We store your IP address entered by the Internet Service Provider (ISP) as well as the date and time of registration to be able to trace possible misuse of your email address at a later time. The data we collect when registering for the newsletter is used strictly for the intended purpose.

You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending a corresponding message to the data controller mentioned at the beginning. After successful unsubscription, your email address will be immediately deleted from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this declaration.

8) Data Processing for Contract Processing

8.1 To process the contract, we work with the following service provider(s) who support us wholly or partially in carrying out concluded contracts. Certain personal data is transmitted to these service providers in accordance with the following information.

8.2 Use of payment service providers

- PayPal

This website offers one or more online payment methods from the following provider: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

When selecting a payment method from the provider where you make an advance payment, your payment data communicated during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order is forwarded to them in accordance with Art. 6 Para. 1 lit. b GDPR. The transfer of your data in this case is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

When selecting a payment method where we make an advance payment, you will also be asked during the ordering process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and possibly data on an alternative payment method).

To safeguard our legitimate interest in determining your creditworthiness in such cases, this data is forwarded by us to the provider for the purpose of a credit check in accordance with Art. 6 Para. 1 lit. f GDPR. The provider checks based on the personal data you provided as well as other data (such as shopping cart, invoice amount, order history, payment experience) whether the payment option you selected can be granted in view of payment and/or default risks.

The credit information may contain probability values (so-called score values). Insofar as score values are included in the result of the credit information, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things but not exclusively, is included in the calculation of score values.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractual payment processing.

- Stripe

This website offers one or more online payment methods from the following provider: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland

When selecting a payment method from the provider where you make an advance payment (such as credit card payment), your payment data communicated during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order is forwarded to them in accordance with Art. 6 Para. 1 lit. b GDPR. The transfer of your data in this case is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

When selecting a payment method where the provider makes an advance payment (such as invoice or installment purchase or direct debit), you will also be asked during the ordering process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and possibly data on an alternative payment method).

To safeguard our legitimate interest in determining the creditworthiness of our customers, this data is forwarded by us to the provider for the purpose of a credit check in accordance with Art. 6 Para. 1 lit. f GDPR. The provider checks based on the personal data you provided as well as other data (such as shopping cart, invoice amount, order history, payment experience) whether the payment option you selected can be granted in view of payment and/or default risks.

The credit information may contain probability values (so-called score values). Insofar as score values are included in the result of the credit information, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things but not exclusively, is included in the calculation of score values.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractual payment processing.

8.3 Electronic termination option for continuing obligations with consumers

Consumers who have entered into contracts for paid continuing obligations (such as subscription contracts) on this website have the option to terminate them via an electronic button in accordance with the applicable termination periods.

Activating the button leads to a confirmation page on which the consumer can provide more details about the termination, clearly identify themselves, and subsequently declare their termination electronically.

The collection of personal data and its transmission to us is carried out in accordance with Art. 6 Para. 1 lit. b GDPR and only to the extent necessary for the proper processing of the termination. Also based on Art. 6 Para. 1 lit. b GDPR, the provided personal data is used to confirm the receipt of the termination declaration and the termination date electronically in text form. Another legal basis for processing is Art. 6 Para. 1 lit. c GDPR. We are legally obligated to provide an electronic termination option for consumer contracts for paid continuing obligations concluded through electronic commerce.

9) Website Functionalities

9.1 Google Sign-In

On our website, we provide a single sign-on function from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

In addition to data transmission to the above-mentioned provider location, data may also be transmitted to: Google LLC, USA

If you have an account with the provider, you can register with these account data to create a user account or register on our website.

When visiting this page, a direct connection between your browser and the provider's servers can be established via this login function, even if you do not have an account with the provider or are not logged into such an account. The provider thereby receives the information that you have visited our page. The information collected in this respect (possibly including your IP address) is transmitted directly from your browser to a server of the provider and stored there. However, the information is not used to personally identify you and is not passed on to third parties.

These data processing operations are carried out in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in a user-friendly and interactive design of our online presence.

If you activate the login button to register on our website with the data from your account with the provider, the provider transmits exclusively based on your explicit consent in accordance with Art. 6 Para. 1 lit. a GDPR the general and publicly accessible information stored in your account (user ID, name, address, email address, age and gender) to us.

We store and use the data transmitted by the provider to set up a user account with the necessary data (salutation, first name, last name, address data, country, email address, date of birth), provided you have released them to the provider. Conversely, based on your consent, data (e.g., information about your browsing or purchasing behavior) can be transferred from us to your account with the provider.

The given consent can be withdrawn at any time with effect for the future from us.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.

Further information on Google's privacy policy can be found here: https://business.safety.google/intl/de/privacy/

9.2 TrustPilot

On our website, graphic elements from the following provider are embedded to display external customer reviews and/or an externally awarded quality seal:  Trustpilot A/S, Pilestraede 58, 1112 Copenhagen, Denmark

When you access a page of our website that contains such graphic elements, your browser establishes a direct connection to the provider's servers to load the elements properly. Certain browser information, including your IP address, is transmitted to the provider.

If personal data is also processed in this process, this is done in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in the optimal marketing of our offer and the attractive design of our website.

9.3 Google Customer Reviews (formerly Google Trusted Store Program)

We work with Google as part of the "Google Customer Reviews" program. The provider is Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). This program gives us the opportunity to obtain customer reviews from users of our website. After a purchase on our website, you will be asked whether you would like to participate in an email survey from Google.

If you give your consent in accordance with Art. 6 Para. 1 lit. a GDPR, we transmit your email address to Google. You will receive an email from Google Customer Reviews asking you to rate the shopping experience on our website. The rating you give is then combined with our other ratings and displayed in our Google Customer Reviews logo as well as in our Merchant Center dashboard. Your rating is also used for Google Seller Ratings. As part of using Google Customer Reviews, personal data may also be transmitted to Google LLC servers in the USA.

You can withdraw your consent at any time by sending a message to the data controller or to Google.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.

Further information on Google's privacy policy can be found here: https://business.safety.google/intl/de/privacy/

10) Tools and Other

- Lexware Office

For accounting purposes, we use the service of cloud-based accounting software from the following provider: Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany

The provider processes incoming and outgoing invoices as well as possibly the bank movements of our company to automatically capture invoices, match them to transactions, and create financial accounting from this in a semi-automated process.

If personal data is also processed in this process, the processing is based on our legitimate interest in efficient organization and documentation of our business processes in accordance with Art. 6 Para. 1 lit. f GDPR.

11) Rights of the Data Subject

11.1 The applicable data protection law grants you the following data subject rights (information and intervention rights) vis-à-vis the data controller regarding the processing of your personal data, whereby reference is made to the stated legal basis for the respective exercise requirements:

  • Right of access according to Art. 15 GDPR;
  • Right to rectification according to Art. 16 GDPR;
  • Right to erasure according to Art. 17 GDPR;
  • Right to restriction of processing according to Art. 18 GDPR;
  • Right to notification according to Art. 19 GDPR;
  • Right to data portability according to Art. 20 GDPR;
  • Right to withdraw given consent according to Art. 7 Para. 3 GDPR;
  • Right to lodge a complaint according to Art. 77 GDPR.

11.2 RIGHT TO OBJECT

IF WE PROCESS YOUR PERSONAL DATA BASED ON OUR OVERRIDING LEGITIMATE INTEREST AS PART OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THIS PROCESSING FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION WITH EFFECT FOR THE FUTURE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FREEDOMS, OR IF THE PROCESSING SERVES THE ASSERTION, EXERCISE OR DEFENSE OF LEGAL CLAIMS.

IF YOUR PERSONAL DATA IS PROCESSED BY US TO CONDUCT DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH ADVERTISING. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.

12) Duration of Storage of Personal Data

The duration of storage of personal data is determined by the respective legal basis, the processing purpose and – if applicable – additionally by the respective statutory retention period (e.g., commercial and tax retention periods).

When processing personal data based on explicit consent according to Art. 6 Para. 1 lit. a GDPR, the data concerned is stored until you withdraw your consent.

If statutory retention periods exist for data processed in the context of legal or quasi-legal obligations based on Art. 6 Para. 1 lit. b GDPR, this data is routinely deleted after the retention periods expire, provided it is no longer required for contract fulfillment or contract initiation and/or we have no legitimate interest in continued storage.

When processing personal data based on Art. 6 Para. 1 lit. f GDPR, this data is stored until you exercise your right to object according to Art. 21 Para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights and freedoms, or the processing serves the assertion, exercise or defense of legal claims.

When processing personal data for direct marketing purposes based on Art. 6 Para. 1 lit. f GDPR, this data is stored until you exercise your right to object according to Art. 21 Para. 2 GDPR.

Unless otherwise specified in the other information in this declaration about specific processing situations, stored personal data is otherwise deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.

This dashboard is made with love by Projectmakers