Data Protection

–––––––––––––––––––

Privacy Policy

––––––––––––––––––––

1) Introduction and Contact Details of the Data Controller

1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data is any data that can be used to personally identify you.

1.2 The data controller for this website within the meaning of the General Data Protection Regulation (GDPR) is Rene Goth, Heeresbergstraße 24, 07549 Gera, Germany, Tel.: +49 172 7608618, Email: info@carboproject.de. The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

2) Data Collection When You Visit Our Website

When you use our website for purely informational purposes, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the website server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:

- The website you visited

- Date and time of access

- Amount of data sent in bytes

- Source/referrer from which you accessed the page

- Browser used

- Operating system used

- IP address used (possibly in anonymized form)

This processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be disclosed or used for any other purpose. However, we reserve the right to subsequently review the server log files should there be concrete indications of unlawful use.

3) Cookies

To make your visit to our website more attractive and to enable the use of certain functions, we use cookies, which are small text files that are stored on your device. Some of these cookies are automatically deleted after you close your browser (so-called "session cookies"), while others remain on your device for a longer period and allow us to save your website settings (so-called "persistent cookies"). In the latter case, you can find information about the storage period in your web browser's cookie settings.

If any of the cookies we use also process personal data, this processing is carried out in accordance with Article 6(1)(b) GDPR for the performance of the contract, in accordance with Article 6(1)(a) GDPR if you have given your consent, or in accordance with Article 6(1)(f) GDPR to protect our legitimate interests in ensuring the best possible website functionality and a user-friendly and effective website experience.

You can configure your browser to notify you when cookies are being set, allowing you to decide whether to accept them individually, or to block cookies in certain cases or entirely.

Please note that if you do not accept cookies, the functionality of our website may be limited.

4) Contacting Us

When you contact us (e.g., via contact form or email), personal data is processed solely for the purpose of handling and responding to your inquiry and only to the extent necessary.

The legal basis for processing this data is our legitimate interest in responding to your inquiry pursuant to Art. 6 para. 1 lit. f GDPR. If your contact is aimed at a contract, the additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted when it is clear from the circumstances that the matter has been resolved and provided that no statutory retention obligations apply.

5) Data Processing When Opening a Customer Account

In accordance with Article 6(1)(b) GDPR, personal data will continue to be collected and processed to the extent necessary if you provide it to us when opening a customer account. The data required for account opening is indicated in the input fields of the corresponding form on our website. You

can delete your customer account at any time by sending a message to the above address of the data controller. After your customer account has been deleted, your data will be deleted provided that all contracts concluded through it have been fully processed, no statutory retention periods apply, and we have no legitimate interest in continuing to store the data.

6) Use of Customer Data for Direct Marketing

Subscription to our Email Newsletter

When you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information required for sending the newsletter is your email address. Providing further information is voluntary and is used to personalize our communications with you. We use the so-called double opt-in procedure for sending the newsletter, which ensures that you only receive newsletters after you have expressly confirmed your consent to receive them by clicking a verification link sent to the specified email address.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 Para. 1 lit. a GDPR. We store your IP address, which is registered by your Internet Service Provider (ISP), as well as the date and time of registration, in order to be able to trace any potential misuse of your email address at a later date. The data we collect when you subscribe to the newsletter is used strictly for the intended purpose.

You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending a message to the data controller named above. After unsubscribing, your email address will be immediately deleted from our newsletter mailing list, unless you have expressly consented to further use of your data or we reserve the right to use your data for other purposes permitted by law, which we will inform you about in this privacy policy.

7) Data Processing for Order Fulfillment

7.1 To the extent necessary for contract fulfillment for delivery and payment purposes, the personal data we collect will be forwarded to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 Para. 1 lit. b GDPR.

If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we process the contact details you provided when placing your order in order to inform you personally within the scope of our legal information obligations pursuant to Art. 6 Para. 1 lit. c GDPR. Your contact details will be used strictly for the purpose of notifying you about updates owed to you and will only be processed by us to the extent necessary for the respective information.

Furthermore, we work with the following service provider(s) to process your order, who support us in whole or in part in the performance of concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.

7.2 Transfer of personal data to shipping service providers

- Deutsche Post

We use the following provider as our transport service provider: Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany.

In accordance with Article 6 Paragraph 1 Letter a of the GDPR, we will forward your email address and/or telephone number to the provider before delivery of the goods for the purpose of coordinating a delivery date or announcing the delivery, provided you have given your express consent during the ordering process. Otherwise, in accordance with Article 6 Paragraph 1 Letter b of the GDPR, we will only forward the recipient's name and delivery address to the provider for the purpose of delivery. This transfer only takes place to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible. You

can withdraw your consent at any time with effect for the future by contacting the data controller named above or the provider.

- DHL

We use the following provider as our transport service provider: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany

We will forward your email address and/or telephone number to the supplier before delivery of the goods in accordance with Article 6 Paragraph 1 Letter a of the GDPR for the purpose of coordinating a delivery date or announcing the delivery, provided you have given your express consent during the ordering process. Otherwise, for the purpose of delivery in accordance with Article 6 Paragraph 1 Letter b of the GDPR, we will only forward the recipient's name and delivery address to the supplier. This data is only shared to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the supplier or delivery notification is not possible.

You can withdraw your consent at any time with effect for the future by contacting the data controller named above or the supplier.

- DHL Express

: We use the following transport service provider: DHL Express Germany GmbH, Heinrich-Brüning-Str. 5, 53113 Bonn, Germany.

We will forward your email address and/or telephone number to the supplier before delivery of the goods in accordance with Article 6 Paragraph 1 Letter a of the GDPR for the purpose of coordinating a delivery date or announcing the delivery, provided you have given your express consent during the ordering process. Otherwise, for the purpose of delivery in accordance with Article 6 Paragraph 1 Letter b of the GDPR, we will only forward the recipient's name and delivery address to the supplier. This data will only be shared to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the supplier or delivery notification is not possible.

You can withdraw your consent at any time with effect for the future by contacting the data controller named above or the supplier.

- DPD:

We use the following transport service provider: DPD Deutschland GmbH, Wailandtstraße 1, 63741 Aschaffenburg, Germany.

In accordance with Article 6 Paragraph 1 Letter a of the GDPR, we will forward your email address and/or telephone number to the provider before delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided you have given your express consent during the ordering process. Otherwise, in accordance with Article 6 Paragraph 1 Letter b of the GDPR, we will only forward the recipient's name and delivery address to the provider for the purpose of delivery. This data is only shared to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.

You can withdraw your consent at any time with effect for the future by contacting the data controller named above or the provider.

- FedEx

We use the following shipping provider: FedEx Express Germany GmbH, Langer Kornweg 34 k, 65451 Kelsterbach, Germany.

In accordance with Article 6 Paragraph 1 Letter a of the GDPR, we will forward your email address and/or telephone number to the provider before delivery of the goods for the purpose of coordinating a delivery date or providing delivery notification, provided you have given your express consent during the ordering process. Otherwise, in accordance with Article 6 Paragraph 1 Letter b of the GDPR, we will only forward the recipient's name and delivery address to the provider for the purpose of delivery. This data is only shared to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.

You can withdraw your consent at any time with effect for the future by contacting the data controller named above or the provider.

- GLS:

We use the following provider as our transport service provider: General Logistics Systems Germany GmbH & Co. OHG, GLS Germany-Straße 1 – 7, 36286 Neuenstein, Germany.

In accordance with Article 6 Paragraph 1 Letter a of the GDPR, we will forward your email address and/or telephone number to the provider before delivery of the goods for the purpose of coordinating a delivery date or announcing the delivery, provided you have given your express consent during the ordering process. Otherwise, in accordance with Article 6 Paragraph 1 Letter b of the GDPR, we will only forward the recipient's name and delivery address to the provider for the purpose of delivery. This data is only shared to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible. You

can withdraw your consent at any time with effect for the future by contacting the data controller named above or the provider.

- Hermes:

As a transport service provider, we use the following provider: Hermes Logistik Gruppe Deutschland GmbH, Essener Straße 89, 22419 Hamburg, Germany.

In accordance with Article 6 Paragraph 1 Letter a of the GDPR, we will forward your email address and/or telephone number to the provider before delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided you have given your express consent during the ordering process. Otherwise, in accordance with Article 6 Paragraph 1 Letter b of the GDPR, we will only forward the recipient's name and delivery address to the provider for the purpose of delivery. This data is only shared to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.

You can withdraw your consent at any time with effect for the future by contacting the data controller named above or the provider.

- Kühne+Nagel.

We use the following provider as our transport service provider: Kühne + Nagel AG & Co. KG, Wilhelm-Kaisen-Brücke 1, 28195 Bremen.

In accordance with Article 6 Paragraph 1 Letter a of the GDPR, we will forward your email address and/or telephone number to the provider before delivery of the goods for the purpose of coordinating a delivery date or announcing the delivery, provided you have given your express consent during the ordering process. Otherwise, in accordance with Article 6 Paragraph 1 Letter b of the GDPR, we will only forward the recipient's name and delivery address to the provider for the purpose of delivery. This data is only shared to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible. You

can withdraw your consent at any time with effect for the future by contacting the data controller named above or the provider.

- Schenker:

As a transport service provider, we use the following provider: Schenker Deutschland AG, Lyoner Straße 15, 60528 Frankfurt am Main, Germany.

In accordance with Article 6 Paragraph 1 Letter a of the GDPR, we will forward your email address and/or telephone number to the provider before delivery of the goods for the purpose of coordinating a delivery date or announcing the delivery, provided you have given your express consent during the ordering process. Otherwise, in accordance with Article 6 Paragraph 1 Letter b of the GDPR, we will only forward the recipient's name and delivery address to the provider for the purpose of delivery. This data is only shared to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.

You can withdraw your consent at any time with effect for the future by contacting the data controller named above or the provider.

- Trans-o-flex

As a transport service provider, we use the following provider: trans-o-flex Express GmbH & Co. KGaA, Hertzstraße 10, 69469 Weinheim, Germany

We will forward your email address and/or telephone number to the supplier before delivery of the goods in accordance with Article 6 Paragraph 1 Letter a of the GDPR for the purpose of coordinating a delivery date or announcing the delivery, provided you have given your express consent during the ordering process. Otherwise, for the purpose of delivery in accordance with Article 6 Paragraph 1 Letter b of the GDPR, we will only forward the recipient's name and delivery address to the supplier. This data will only be shared to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the supplier or delivery notification is not possible.

You can withdraw your consent at any time with effect for the future by contacting the data controller named above or the supplier.

- UPS.

As a transport service provider, we use the following provider: United Parcel Service Deutschland Inc. & Co. OHG, Görlitzer Straße 1, 41460 Neuss, Germany.

In accordance with Article 6 Paragraph 1 Letter a of the GDPR, we will forward your email address and/or telephone number to the provider before delivery of the goods for the purpose of coordinating a delivery date or announcing the delivery, provided you have given your express consent during the ordering process. Otherwise, in accordance with Article 6 Paragraph 1 Letter b of the GDPR, we will only forward the recipient's name and delivery address to the provider for the purpose of delivery. This data is only shared to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible. You

can withdraw your consent at any time with effect for the future by contacting the data controller named above or the provider.

7.3 Use of Payment Service Providers

- Apple Pay

If you choose the "Apple Pay" payment method from Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, payment processing is handled via the "Apple Pay" function of your iOS, watchOS, or macOS device by charging a payment card stored with "Apple Pay." Apple Pay uses security features integrated into your device's hardware and software to protect your transactions. Authorizing a payment requires entering a code you previously set and verifying it using your device's "Face ID" or "Touch ID" function.

For payment processing purposes, the information you provide during the ordering process, along with information about your order, is transmitted to Apple in encrypted form. Apple then re-encrypts this data with a developer-specific key before transmitting it to the payment service provider of the payment card stored in Apple Pay. This encryption ensures that only the website where the purchase was made can access the payment data. After the payment has been processed, Apple sends your device account number and a transaction-specific, dynamic security code to the originating website to confirm the payment success.

If personal data is processed during these transmissions, it is processed exclusively for the purpose of payment processing in accordance with Article 6(1)(b) GDPR.

Apple retains anonymized transaction data, including the approximate purchase amount, the approximate date and time, and whether the transaction was successfully completed. This anonymization completely eliminates any possibility of identifying individuals. Apple uses the anonymized data to improve Apple Pay and other Apple products and services.

When you use Apple Pay on your iPhone or Apple Watch to complete a purchase you made through Safari on your Mac, your Mac and the authorizing device communicate via an encrypted channel on Apple's servers. Apple does not process or store any of this information in a format that can identify you personally. You can disable the ability to use Apple Pay on your Mac in your iPhone settings. Go to "Wallet & Apple Pay" and turn off "Allow Payments on Mac." For

more information about Apple Pay privacy, please visit the following web address: https://support.apple.com/de-de/HT203027

- giropay.

This website offers one or more online payment methods from the following provider: paydirekt GmbH, Stephanstr. 14-16, 60313 Frankfurt am Main, Germany.

When selecting a payment method from the provider that requires advance payment (such as credit card payment), your payment details provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number), as well as information about the contents of your order, will be transmitted to the provider in accordance with Article 6 Paragraph 1 Letter b GDPR. In this case, your data will be transmitted exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

- Klarna

This website offers one or more online payment methods from the following provider: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden.

If you select a payment method from this provider where you pay in advance (e.g., credit card payment), your payment details provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number), as well as information about the contents of your order, will be transmitted to them in accordance with Article 6 Paragraph 1 Letter b GDPR. In this case, your data will be transmitted exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

If you select a payment method where the provider pays in advance (e.g., invoice, installment payment, or direct debit), you will also be asked to provide certain personal data during the ordering process (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and, if applicable, details of an alternative payment method).

To protect our legitimate interest in assessing our customers' creditworthiness, we forward this data to the provider for the purpose of a credit check in accordance with Article 6(1)(f) GDPR. Based on the personal data you provide, as well as other data (such as shopping cart contents, invoice amount, order history, and payment history), the provider checks whether your selected payment option can be granted with regard to payment and/or default risks.

In addition to internal provider criteria, identity and credit information from the following credit agencies may also be included in the decision-making process for the application review, in accordance with Article 6(1)(f) GDPR:

https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies

. The credit report may contain probability values ​​(so-called score values). If score values ​​are included in the credit report, they are based on a scientifically recognized mathematical-statistical method. Address data is one of the factors, but not the only one, used in calculating the score values.

You can object to this processing of your data at any time by contacting us or the provider. However, the provider may still be entitled to process your personal data if this is necessary for processing payments in accordance with the contract.

- PayPal:

This website offers one or more online payment methods from the following provider: PayPal (Europe) Sarl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg

When you select a payment method offered by the provider that requires you to pay in advance, your payment details provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number), as well as information about the contents of your order, will be transmitted to the provider in accordance with Article 6 Paragraph 1 Letter b of the GDPR. In this case, your data will be transmitted exclusively for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

If you select a payment method where we provide the service in advance, you will also be asked to provide certain personal data during the ordering process (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and, if applicable, details of an alternative payment method).

In such cases, to protect our legitimate interest in verifying your creditworthiness, we will forward this data to the provider for the purpose of a credit check in accordance with Article 6 Paragraph 1 Letter f of the GDPR. Based on the personal data you provide, as well as other data (such as shopping cart contents, invoice amount, order history, and payment history), the provider checks whether your selected payment method can be granted with regard to payment and/or default risks.

The credit report may contain probability values ​​(so-called score values). If score values ​​are included in the credit report, they are based on a scientifically recognized mathematical-statistical method. Address data is among the data used to calculate the score values, but is not the only factor.

You can object to this processing of your data at any time by contacting us or the provider. However, the provider may still be entitled to process your personal data if this is necessary for processing payments in accordance with the contract.

- PayPal Checkout:

This website uses PayPal Checkout, an online payment system from PayPal, which consists of PayPal's own payment methods and local payment methods from third-party providers.

When paying via PayPal, credit card via PayPal, direct debit via PayPal, or – if offered – "Pay Later" via PayPal, we forward your payment data to PayPal (Europe) Sarl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") for payment processing. This transfer is carried out in accordance with Article 6 Paragraph 1 Letter b GDPR and only to the extent necessary for payment processing.

For the payment methods credit card via PayPal, direct debit via PayPal, or – if offered – "Pay later" via PayPal, PayPal reserves the right to conduct a credit check. For this purpose, your payment data may be forwarded to credit agencies in accordance with Art. 6 Para. 1 lit. f GDPR, based on PayPal's legitimate interest in assessing your creditworthiness. PayPal uses the result of the credit check regarding the statistical probability of payment default to decide whether to offer the respective payment method. The credit check may include probability values ​​(so-called score values). If score values ​​are included in the result of the credit check, they are based on a scientifically recognized mathematical-statistical procedure. Address data is among the data used to calculate the score values, but is not the only factor. You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for the contractual processing of payments.

If the PayPal payment method "purchase on account" is available and selected, your payment data will first be transmitted to PayPal to prepare the payment. PayPal will then forward this data to Ratepay GmbH, Franklinstrasse 28-29, 10587 Berlin ("Ratepay") for payment processing. The legal basis for this is Article 6(1)(b) GDPR. In this case, Ratepay conducts an identity and credit check on its own behalf to determine your creditworthiness in accordance with the principle already mentioned above and, based on its legitimate interest in determining creditworthiness pursuant to Article 6(1)(f) GDPR, forwards your payment data to credit agencies. A list of the credit agencies that Ratepay may use can be found here: https://www.ratepay.com/legal-payment-creditagencies/

If you use a payment method from a local third-party provider, your payment data will first be forwarded to PayPal in accordance with Article 6(1)(b) GDPR to prepare the payment. Depending on your selection of an available local payment method, PayPal will then transmit your payment data to the respective provider in accordance with Art. 6 para. 1 lit. b GDPR for the purpose of processing the payment:

- Apple Pay (Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland)

- Google Pay (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland)

- iDeal (Currence Holding BV, Beethovenstraat 300 Amsterdam, Netherlands)

- bancontact (Bancontact Payconiq Company, Rue d'Arlon 82, 1040 Brussels, Belgium)

- blik (Polski Standard Płatności sp. z o.o., ul. Czerniakowska 87A, 00-718 Warsaw, Poland)

- eps (PSA Payment Services Austria GmbH, Handelskai 92, Gate 2,

1200 Vienna, Austria)

- MyBank (PRETA SAS, 40 Rue de Courcelles, F-75008 Paris, France)

- Przelewy24 (PayPro SA, Kanclerska 15A, 60-326 Poznań, Poland)

For further information on data protection, please refer to PayPal's privacy policy: https://www.paypal.com/de/legalhub/paypal/privacy-full

- Shopify Payments

This website offers one or more online payment methods from the following provider: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.

When selecting a payment method from this provider, If you make an advance payment (e.g., credit card payment), your payment details provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number) as well as information about the contents of your order will be transmitted to the payment provider in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, your data will be transmitted exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

- Instant bank transfer.

One or more online payment methods from the following provider are available on this website: Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden.

If you select a payment method from this provider where you make an advance payment (e.g., credit card payment), your payment details provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number) as well as information about the contents of your order will be transmitted to the payment provider in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, your data will only be shared with the provider for the purpose of payment processing and only to the extent necessary for this purpose.

7.4 Sanctions List Check

In the context of initiating business relationships and processing orders, we reserve the right to compare the personal data you provide with information from sanctions lists of the European Union and/or its individual member states and to decide on the establishment of a business relationship or the execution of the order based on the results of this comparison.

This data processing is carried out in accordance with Article 6 Paragraph 1 Letter c GDPR based on our legal obligation to check and ensure that we do not enter into business relationships with sanctioned natural or legal persons and thus prevent the provision of resources to such persons.

7.5 Electronic Cancellation Function for Distance Contracts

Consumers who conclude contracts on this website for which a statutory right of cancellation exists have the option of declaring their cancellation via an electronic cancellation function in accordance with the applicable cancellation regulations.

We use a solution from the following provider for the provision of the electronic cancellation function: ECOMBEAT, Garnisonsgasse 4/11, Vienna, 1090, AT.

When using the cancellation function, in addition to information to identify the contract to be cancelled, further personal information such as the consumer's first and last name and email address must also be provided or confirmed.

This information is initially collected by the provider based on our legitimate interest in a user-friendly, stable, and process-optimized solution pursuant to Art. 6 para. 1 lit. f GDPR. It is then used to confirm receipt of the withdrawal notice on our behalf via email and finally transmitted to us. We subsequently process the transmitted information for the proper handling of the withdrawal pursuant to Art. 6 para. 1 lit. b GDPR and Art. 6 para. 1 lit. c GDPR, based on our legal obligation to provide an electronic withdrawal function for paid distance selling contracts for consumers.

The information collected by the provider is routinely deleted after the withdrawal has been fully processed, unless statutory retention obligations apply.

We have concluded a data processing agreement with the provider, which protects the data processed within the scope of the withdrawal function and prohibits unauthorized disclosure to third parties.

8) Web Analytics Services

Google (Universal) Analytics

This website uses Google (Universal) Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables analysis of your use of our website.

By default, Google (Universal) Analytics sets cookies when you visit the website. These cookies are small text files stored on your device and collect certain information. This information includes your IP address, which Google truncates by removing the last digits to prevent it from being directly linked to you.

The information is transmitted to and processed by Google on servers in the United States. This may also involve transfers to Google LLC, which is located in the USA.

Google uses the collected information on our behalf to evaluate your use of the website, to compile reports on website activity for us, and to provide other services relating to website activity and internet usage. The truncated IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. The data collected through the use of Google (Universal) Analytics is stored for two months and then deleted.

All processing described above, in particular the setting of cookies on your device, only takes place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR.

Without your consent, Google (Universal) Analytics will not be used during your visit to our website. You can revoke your consent at any time with effect for the future. To exercise your right of revocation, please deactivate this service using the "Cookie Consent Tool" provided on the website.

We have concluded a data processing agreement with Google, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

Further legal information on Google (Universal) Analytics can be found at https://business.safety.google/intl/de/privacy/, https://policies.google.com/privacy?hl=de&gl=de and at https://policies.google.com/technologies/partner-sites.

Demographic characteristics

Google (Universal) Analytics uses the special feature "demographic characteristics" to generate statistics about the age, gender, and interests of website visitors. This is achieved by analyzing advertising and information from third-party providers. This allows for the identification of target groups for marketing activities. However, the collected data cannot be linked to any specific individual and is deleted after a storage period of two months.

Google Signals:

As an extension to Google (Universal) Analytics, this website may use Google Signals to generate cross-device reports. If you have enabled personalized ads and linked your devices to your Google account, Google may, subject to your consent to the use of Google Analytics pursuant to Art. 6 Para. 1 lit. a GDPR, analyze your usage behavior across devices and create database models, including those related to cross-device conversions. We do not receive any personally identifiable information from Google, only statistics. If you wish to stop cross-device analysis, you can deactivate the "Personalized advertising" feature in your Google account settings. To do this, follow the instructions on this page: https://support.google.com/My-Ad-Center-Help/answer/12155764?hl=de

Further information about Google Signals can be found at the following link: https://support.google.com/analytics/answer/7532985?hl=de

UserIDs:

As an extension to Google (Universal) Analytics, the "UserIDs" function may be used on this website. If you have consented to the use of Google (Universal) Analytics in accordance with Art. 6 Para. 1 lit. a GDPR, have created an account on this website, and log in to this account on different devices, your activities, including conversions, can be analyzed across devices.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

9) Website Functionalities

- Google reCAPTCHA

This website uses the CAPTCHA service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

Data may also be transferred to Google LLC, USA.

The provider uses "Google Fonts," i.e., fonts downloaded from the internet by Google, for the visual design of the CAPTCHA window. No further information beyond that already transmitted to Google via the reCAPTCHA functionality is processed.

The service verifies whether an entry is made by a human or abusively by automated processing and blocks spam, DDoS attacks, and similar automated malicious access. To ensure that an action is performed by a human and not an automated bot, the provider collects the IP address of the device used, identification data of the browser and operating system used, as well as the date and duration of the visit, and transmits this information to the provider's servers for evaluation. Cookies may be used in this process; these are small text files that are stored in the browser of your device.

If the processing described above is based on cookies, they will only be set if you have given us your explicit consent in accordance with Article 6 Paragraph 1 Letter a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

If the processing described above is carried out without the use of cookies, the legal basis is our legitimate interest in establishing individual responsibility on the internet and preventing misuse and spam in accordance with Article 6 Paragraph 1 Letter f GDPR.

We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

10) Tools and Other Information:

Cookie Consent Tool

This website uses a so-called "cookie consent tool" to obtain effective user consent for cookies and cookie-based applications that require consent. The "cookie consent tool" is displayed to users upon visiting the site as an interactive user interface, where consent for specific cookies and/or cookie-based applications can be granted by ticking boxes. By using this tool, all cookies/services requiring consent are only loaded if the respective user grants the corresponding consent by ticking the boxes. This ensures that such cookies are only placed on the user's device if consent has been given.

The tool sets technically necessary cookies to save your cookie preferences. No personal user data is processed in this process.

If, in individual cases, the processing of personal data (such as the IP address) occurs for the purpose of storing, assigning, or logging cookie settings, this is done in accordance with Article 6(1)(f) GDPR based on our legitimate interest in legally compliant, user-specific, and user-friendly cookie consent management and thus in the legally compliant design of our website.

A further legal basis for the processing is Article 6(1)(c) GDPR. As the data controller, we are legally obligated to make the use of cookies that are not technically necessary dependent on the respective user's consent.

Where necessary, we have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

Further information about the operator and the settings options of the cookie consent tool can be found directly in the corresponding user interface on our website.

11) Rights of the Data Subject

11.1 The applicable data protection law grants you the following rights as a data subject vis-à-vis the controller with regard to the processing of your personal data (rights of access and intervention), whereby reference is made to the legal basis listed for the respective requirements for exercising these rights:

-

Right of access pursuant to Art. 15 GDPR; -

Right to rectification pursuant to Art. 16 GDPR;

- Right to erasure pursuant to Art. 17 GDPR;

- Right to restriction of processing pursuant to Art. 18 GDPR; - Right to be

informed pursuant to Art. 19 GDPR; - Right to data portability pursuant to Art. 20 GDPR;

- Right to withdraw consent pursuant to Art. 7 para. 3 GDPR;

- Right to lodge a complaint pursuant to Art. 77 GDPR.

11.2 Right to object:

If we process your personal data based on our overriding legitimate interest as part of a balancing of interests, you have the right to object to this processing at any time, on grounds relating to your particular situation, with effect for the future.

If you exercise your right to object, we will cease processing the data in question. Further processing will only be permitted if we can demonstrate compelling legitimate grounds for the processing which override your interests, fundamental rights and freedoms, or if the processing serves the establishment, exercise or defense of legal claims.

If your personal data is processed by us for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing. You can exercise your right to object as described above.

If you exercise your right to object, we will cease processing the data in question for direct marketing purposes.

12) Duration of Storage of Personal Data

The duration of storage of personal data is determined by the respective legal basis, the purpose of processing, and – where applicable – additionally by the respective statutory retention period (e.g., commercial and tax law retention periods).

When processing personal data based on explicit consent pursuant to Art. 6 para. 1 lit. a GDPR, the data concerned will be stored until you withdraw your consent. If

statutory retention periods exist for data processed in the context of contractual or quasi-contractual obligations based on Art. 6 para. 1 lit. b GDPR, this data will be routinely deleted after the expiry of the retention periods, provided that it is no longer required for the performance of a contract or for initiating a contract and/or we no longer have a legitimate interest in its continued storage.

When processing personal data based on Article 6(1)(f) GDPR, this data will be stored until you exercise your right to object pursuant to Article 21(1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the purpose of establishing, exercising or defending legal claims.

When processing personal data for direct marketing purposes based on Article 6(1)(f) GDPR, this data will be stored until you exercise your right to object pursuant to Article 21(2) GDPR.

Unless otherwise specified in this privacy policy regarding specific processing situations, stored personal data will be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.

Copyright notice: This privacy policy was created by the specialist lawyers of the IT law firm and is protected by copyright (https://www.it-recht-kanzlei.de)

Stand: 18.06.2026

Contact us

Do you have any questions?