1) Introduction and Contact Details of the Data Controller

1.1 We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about the handling of your personal data when using our website. Personal data refers to all data by which you can be personally identified.

1.2 The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is CMK Tonerstore GmbH, Hofbauergasse 1/1b, 1120 Vienna, Austria, Tel.: +43 699 190 522 22, Email: office@tonerstore.at. The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.

2) Data Collection When Visiting Our Website

2.1 When you use our website for purely informational purposes — i.e. without registering or otherwise submitting information to us — we only collect data that your browser transmits to our server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:

  • The page visited on our website
  • Date and time of access
  • Amount of data transmitted in bytes
  • Source/referrer from which you arrived at the page
  • Browser used
  • Operating system used
  • IP address used (where applicable: in anonymised form)

Processing is carried out pursuant to Art. 6(1)(f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data is not passed on or used for any other purpose. However, we reserve the right to review server log files retrospectively if there are concrete indications of unlawful use.

2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or enquiries to the controller), this website uses SSL/TLS encryption. You can identify an encrypted connection by the "https://" prefix and the padlock icon in your browser's address bar.

3) Hosting & Content Delivery Network

For hosting our website and displaying its content, we use a provider that delivers its services — either directly or through selected sub-processors — exclusively on servers located within the European Union.

All data collected on our website is processed on these servers.

We have entered into a data processing agreement with the provider, which ensures the protection of our visitors' data and prohibits unauthorised disclosure to third parties.

4) Cookies

To make your visit to our website enjoyable and to enable certain features, we use cookies — small text files stored on your device. Some cookies are automatically deleted when you close your browser (so-called "session cookies"), while others remain on your device for a longer period and allow website settings to be saved (so-called "persistent cookies"). In the latter case, you can find the storage duration in your web browser's cookie settings overview.

Where individual cookies we use also process personal data, this is done pursuant to Art. 6(1)(b) GDPR for the performance of a contract, pursuant to Art. 6(1)(a) GDPR where consent has been given, or pursuant to Art. 6(1)(f) GDPR to protect our legitimate interests in providing the best possible functionality of the website and a user-friendly and effective browsing experience.

You can configure your browser to notify you about the placement of cookies and to decide individually whether to accept them, or to reject cookies in certain cases or altogether.

Please note that disabling cookies may limit the functionality of our website.

5) Contact

When you contact us (e.g. via contact form or email), personal data is processed solely for the purpose of handling and responding to your enquiry, and only to the extent necessary for that purpose.

The legal basis for processing this data is our legitimate interest in responding to your enquiry pursuant to Art. 6(1)(f) GDPR. If your contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6(1)(b) GDPR. Your data will be deleted once the circumstances indicate that the matter has been fully resolved and provided no statutory retention obligations apply.

6) Data Processing When Opening a Customer Account

Pursuant to Art. 6(1)(b) GDPR, personal data will continue to be collected and processed to the necessary extent when you provide it to us upon opening a customer account. The data required for account registration can be found in the input form on our website.

You may delete your customer account at any time by sending a message to the controller's address listed above. Once your account is deleted, your data will be erased, provided all contracts concluded through the account have been fully processed, no statutory retention periods apply, and we have no legitimate interest in retaining the data.

7) Use of Customer Data for Direct Marketing

7.1 Email Newsletter Subscription

If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information required to send the newsletter is your email address. Providing additional data is voluntary and is used to address you personally. We use the double opt-in procedure for newsletter delivery, which ensures you only receive newsletters after you have expressly confirmed your consent by clicking a verification link sent to the email address you provided.

By activating the confirmation link, you grant us your consent to use your personal data pursuant to Art. 6(1)(a) GDPR. We store your IP address as registered by your Internet Service Provider (ISP), as well as the date and time of registration, in order to be able to trace any potential misuse of your email address at a later stage. The data collected during newsletter registration is used strictly for its stated purpose.

You may unsubscribe from the newsletter at any time via the designated link in the newsletter or by sending a message to the controller listed above. Upon unsubscription, your email address will be promptly removed from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use it in a manner that is permitted by law and disclosed in this statement.

7.2 Brevo

Our email newsletters and other promotional email communications are sent via the following provider: Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany.

Based on our legitimate interest in effective and user-friendly email marketing, we share the data you provide during registration with this provider pursuant to Art. 6(1)(f) GDPR, so that the provider can send emails on our behalf.

We reserve the right, exclusively on the basis of your express consent pursuant to Art. 6(1)(a) GDPR, to additionally carry out statistical performance analysis of email campaigns using web beacons or tracking pixels embedded in the emails, which can measure open rates and specific interactions with newsletter content. Device information (e.g. time of access, IP address, browser type and operating system) is also collected and analysed in this context, but not merged with other datasets.

You may withdraw your consent to email tracking at any time with effect for the future.

We have entered into a data processing agreement with the provider, which protects our visitors' data and prohibits disclosure to third parties.

8) Data Processing for Order Fulfilment

8.1 To the extent necessary for the fulfilment of contracts for delivery and payment purposes, the personal data we collect is passed on to the commissioned transport company and payment institution pursuant to Art. 6(1)(b) GDPR.

Where we owe you updates for goods with digital elements or digital products under a corresponding contract, we process the contact details provided at the time of ordering to inform you personally of such updates as part of our statutory notification obligations pursuant to Art. 6(1)(c) GDPR. Your contact details are used strictly for the purpose of communicating obligatory updates and are processed by us only to the extent necessary for each such notification.

For order processing, we also work with the following service provider(s), who support us fully or in part in the execution of concluded contracts. Certain personal data is transmitted to these providers as set out below.

8.2 Sendcloud

For shipping, we use the following provider: Sendcloud GmbH, Fürstenrieder Str. 70, 80686 Munich, Germany.

Pursuant to Art. 6(1)(b) GDPR, we share your data exclusively for the purpose of processing your online order. The provider prints shipping labels and transmits shipment data to the commissioned carrier on our behalf. Data is only shared to the extent necessary for order fulfilment.

The provider also sends shipping notifications and delivery status updates on our behalf. For this purpose, pursuant to Art. 6(1)(f) GDPR and based on our legitimate interest in effective and informative customer communication as well as transparent and reliable post-shipment processing — which is also in the customer's interest — we share certain customer data (email address, first and last name, and delivery address) along with the tracking number with the provider.

The data is not passed on to third parties by the provider and is processed exclusively for the purposes stated above. After delivery is complete, the provider deletes the data.

We have entered into a data processing agreement with the provider, which protects our visitors' data and prohibits disclosure to third parties.

8.3 Disclosure of Personal Data to Shipping Service Providers

- GLS

We use the following provider as our transport service: General Logistics Systems Germany GmbH & Co. OHG, GLS Germany-Straße 1 – 7, 36286 Neuenstein, Germany.

We share your email address and/or telephone number with the provider pursuant to Art. 6(1)(a) GDPR prior to delivery of the goods for the purpose of arranging a delivery appointment or providing advance delivery notification, provided you have given your express consent to this during the ordering process. Otherwise, for the purpose of delivery, we share only the recipient's name and delivery address with the provider pursuant to Art. 6(1)(b) GDPR. Data is only shared to the extent necessary for delivery of the goods. In this case, prior arrangement of a delivery appointment or advance notification through the provider is not possible.

Consent may be withdrawn at any time with effect for the future, either with the controller named above or directly with the provider.

8.4 Use of Payment Service Providers

- Amazon Pay

One or more online payment options from the following provider are available on this website: Amazon Payments Europe s.c.a., 38 avenue J.F. Kennedy, L-1855 Luxembourg.

If you select a payment method offered by the provider where you pay in advance (e.g. credit card payment), your payment data provided during the ordering process (including name, address, bank and payment card details, currency and transaction number) as well as information about the contents of your order will be passed on to the provider pursuant to Art. 6(1)(b) GDPR. Your data is shared solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.
- Apple Pay

If you choose the payment method "Apple Pay" from Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, payment is processed via the "Apple Pay" feature on your iOS, watchOS or macOS device by charging a payment card stored in Apple Pay. Apple Pay uses security features integrated into your device's hardware and software to protect your transactions. Authorising a payment therefore requires you to enter a code you previously set up and to verify using the "Face ID" or "Touch ID" feature on your device.

For the purpose of processing the payment, your information provided during the ordering process, along with the details of your order, is transmitted to Apple in encrypted form. Apple then re-encrypts this data with a developer-specific key before transmitting it to the payment service provider of the payment card stored in Apple Pay. The encryption ensures that only the website through which the purchase was made can access the payment data. After the payment is made, Apple sends your device account number and a transaction-specific dynamic security code to the originating website to confirm successful payment.

Where personal data is processed in the described transmissions, processing occurs exclusively for the purpose of payment processing pursuant to Art. 6(1)(b) GDPR.

Apple retains anonymised transaction data, including the approximate purchase amount, approximate date and time, and whether the transaction was completed successfully. Anonymisation fully excludes any link to an individual. Apple uses the anonymised data to improve Apple Pay and other Apple products and services.

When you use Apple Pay on iPhone or Apple Watch to complete a purchase made via Safari on a Mac, the Mac and the authorisation device communicate via an encrypted channel on Apple's servers. Apple does not process or store any of this information in a format that can be used to identify you. You can disable the option to use Apple Pay on your Mac in your iPhone settings. Go to "Wallet & Apple Pay" and disable "Allow Payments on Mac".

Further information on data protection with Apple Pay can be found at: https://support.apple.com/de-de/HT203027
- Bancontact

One or more online payment options from the following provider are available on this website: Bancontact Payconiq Company, Rue d'Arlon 82, 1040 Brussels, Belgium.

If you select a payment method offered by the provider where you pay in advance (e.g. credit card payment), your payment data provided during the ordering process (including name, address, bank and payment card details, currency and transaction number) as well as information about the contents of your order will be passed on to the provider pursuant to Art. 6(1)(b) GDPR. Your data is shared solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.
- Billie GmbH

One or more online payment options from the following provider are available on this website: Billie GmbH, Charlottenstraße 4, 10969 Berlin, Germany.

If you select a payment method offered by the provider where you pay in advance (e.g. credit card payment), your payment data provided during the ordering process (including name, address, bank and payment card details, currency and transaction number) as well as information about the contents of your order will be passed on to the provider pursuant to Art. 6(1)(b) GDPR. Your data is shared solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

If you select a payment method where the provider pays in advance (e.g. purchase on account, instalment purchase, or direct debit), you will also be asked during the ordering process to provide certain personal data (first and last name, street, house number, postcode, city, date of birth, email address, telephone number, and if applicable details of an alternative payment method).

In order to protect our legitimate interest in assessing the creditworthiness of our customers, this data will be forwarded by us to the provider pursuant to Art. 6(1)(f) GDPR for the purpose of a credit check. The provider will assess, on the basis of the personal data you have provided as well as additional data (such as shopping cart, invoice amount, order history, payment experience), whether the payment option you have selected can be granted with regard to payment and/or default risks.

For the purpose of the credit assessment, identity and creditworthiness information from the following credit reference agencies may be included in addition to the provider's internal criteria pursuant to Art. 6(1)(f) GDPR:

  • Creditreform Berlin Wolfram KG, Karl-Heinrich-Ulrichs-Straße 1, 10787 Berlin, Germany
  • Creditreform Boniversum GmbH, Hammfelddamm 13, 41460 Neuss, Germany
  • SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden, Germany
  • Euler Hermes Deutschland, Friedensallee 254, 22763 Hamburg, Germany

The credit report may contain probability values (so-called score values). Where score values are included in the outcome of the credit report, they are based on a scientifically recognised mathematical-statistical procedure. Address data is included in the calculation of score values, among other factors, but not exclusively.

You may object to this processing of your data at any time by sending a message to us or directly to the provider. However, the provider may remain entitled to process your personal data where this is necessary for the contractual processing of payment.
- EPS Bank Transfer

One or more online payment options from the following provider are available on this website: PSA Payment Services Austria GmbH, Handelskai 92, Gate 2, 1200 Vienna, Austria.

If you select a payment method offered by the provider where you pay in advance (e.g. credit card payment), your payment data provided during the ordering process (including name, address, bank and payment card details, currency and transaction number) as well as information about the contents of your order will be passed on to the provider pursuant to Art. 6(1)(b) GDPR. Your data is shared solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.
- Google Pay

If you choose the payment method "Google Pay" from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), payment is processed via the "Google Pay" application on your mobile device running at least Android 4.4 ("KitKat") and equipped with an NFC function, by charging a payment card stored in Google Pay or a verified payment system registered there (e.g. PayPal). For payments via Google Pay exceeding €25.00, prior unlocking of your mobile device using the verification method you have set up (e.g. facial recognition, password, fingerprint or pattern) is required.

For the purpose of processing the payment, your information provided during the ordering process, along with the details of your order, is transmitted to Google. Google then transmits your payment information stored in Google Pay in the form of a one-time transaction number to the originating website, which is used to verify the payment. This transaction number contains no information about your actual payment details stored in Google Pay; it is generated and transmitted as a one-time numerical token. In all transactions via Google Pay, Google acts solely as an intermediary for processing the payment. The transaction is carried out exclusively between the user and the originating website by charging the payment method stored in Google Pay.

Where personal data is processed in the described transmissions, processing occurs exclusively for the purpose of payment processing pursuant to Art. 6(1)(b) GDPR.

Google reserves the right to collect, store and analyse certain transaction-specific information for each transaction made via Google Pay. This includes the date, time and amount of the transaction, the merchant's location and description, a description of the purchased goods or services provided by the merchant, photos you have attached to the transaction, the name and email address of the seller and buyer or sender and recipient, the payment method used, your description of the reason for the transaction, and where applicable any offer associated with the transaction.

According to Google, this processing is carried out exclusively pursuant to Art. 6(1)(f) GDPR on the basis of the legitimate interest in proper accounting, verification of transaction data, and the optimisation and maintenance of the Google Pay service.

Google also reserves the right to combine the processed transaction data with further information collected and stored by Google when you use other Google services.

The Google Pay Terms of Service can be found here:

https://payments.google.com/payments/apis-secure/u/0/get_legal_document?ldo=0&ldt=googlepaytos&ldl=de
Further information on data protection with Google Pay can be found at:
https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice&ldl=de
- iDEAL

One or more online payment options from the following provider are available on this website: Currence Holding BV, Beethovenstraat 300, Amsterdam, Netherlands.

If you select a payment method offered by the provider where you pay in advance (e.g. credit card payment), your payment data provided during the ordering process (including name, address, bank and payment card details, currency and transaction number) as well as information about the contents of your order will be passed on to the provider pursuant to Art. 6(1)(b) GDPR. Your data is shared solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.
- Klarna

One or more online payment options from the following provider are available on this website: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden.

If you select a payment method offered by the provider where you pay in advance (e.g. credit card payment), your payment data provided during the ordering process (including name, address, bank and payment card details, currency and transaction number) as well as information about the contents of your order will be passed on to the provider pursuant to Art. 6(1)(b) GDPR. Your data is shared solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

If you select a payment method where the provider pays in advance (e.g. purchase on account, instalment purchase, or direct debit), you will also be asked during the ordering process to provide certain personal data (first and last name, street, house number, postcode, city, date of birth, email address, telephone number, and if applicable details of an alternative payment method).

In order to protect our legitimate interest in assessing the creditworthiness of our customers, this data will be forwarded by us to the provider pursuant to Art. 6(1)(f) GDPR for the purpose of a credit check. The provider will assess, on the basis of the personal data you have provided as well as additional data (such as shopping cart, invoice amount, order history, payment experience), whether the payment option you have selected can be granted with regard to payment and/or default risks.

For the purpose of the credit assessment, identity and creditworthiness information from the following credit reference agencies may be included in addition to the provider's internal criteria pursuant to Art. 6(1)(f) GDPR:

https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies

The credit report may contain probability values (so-called score values). Where score values are included in the outcome of the credit report, they are based on a scientifically recognised mathematical-statistical procedure. Address data is included in the calculation of score values, among other factors, but not exclusively.

You may object to this processing of your data at any time by sending a message to us or directly to the provider. However, the provider may remain entitled to process your personal data where this is necessary for the contractual processing of payment.
- PayPal

One or more online payment options from the following provider are available on this website: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.

If you select a payment method offered by the provider where you pay in advance, your payment data provided during the ordering process (including name, address, bank and payment card details, currency and transaction number) as well as information about the contents of your order will be passed on to the provider pursuant to Art. 6(1)(b) GDPR. Your data is shared solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

If you select a payment method where we pay in advance, you will also be asked during the ordering process to provide certain personal data (first and last name, street, house number, postcode, city, date of birth, email address, telephone number, and if applicable details of an alternative payment method).

In order to protect our legitimate interest in assessing your creditworthiness in such cases, this data will be forwarded by us to the provider pursuant to Art. 6(1)(f) GDPR for the purpose of a credit check. The provider will assess, on the basis of the personal data you have provided as well as additional data (such as shopping cart, invoice amount, order history, payment experience), whether the payment option you have selected can be granted with regard to payment and/or default risks.

The credit report may contain probability values (so-called score values). Where score values are included in the outcome of the credit report, they are based on a scientifically recognised mathematical-statistical procedure. Address data is included in the calculation of score values, among other factors, but not exclusively.

You may object to this processing of your data at any time by sending a message to us or directly to the provider. However, the provider may remain entitled to process your personal data where this is necessary for the contractual processing of payment.
- Revolut Pay

One or more online payment options from the following provider are available on this website: Revolut Bank UAB, Konstitucijos ave. 21B, 08130 Vilnius, Lithuania.

To process your payment, the payment data provided during the ordering process (including name, address, bank and payment card details, currency and transaction number) as well as information about the contents of your order will be passed on to the provider pursuant to Art. 6(1)(b) GDPR. Your data is shared solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.
- Stripe

One or more online payment options from the following provider are available on this website: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.

If you select a payment method offered by the provider where you pay in advance (e.g. credit card payment), your payment data provided during the ordering process (including name, address, bank and payment card details, currency and transaction number) as well as information about the contents of your order will be passed on to the provider pursuant to Art. 6(1)(b) GDPR. Your data is shared solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

If you select a payment method where the provider pays in advance (e.g. purchase on account, instalment purchase, or direct debit), you will also be asked during the ordering process to provide certain personal data (first and last name, street, house number, postcode, city, date of birth, email address, telephone number, and if applicable details of an alternative payment method).

In order to protect our legitimate interest in assessing the creditworthiness of our customers, this data will be forwarded by us to the provider pursuant to Art. 6(1)(f) GDPR for the purpose of a credit check. The provider will assess, on the basis of the personal data you have provided as well as additional data (such as shopping cart, invoice amount, order history, payment experience), whether the payment option you have selected can be granted with regard to payment and/or default risks.

The credit report may contain probability values (so-called score values). Where score values are included in the outcome of the credit report, they are based on a scientifically recognised mathematical-statistical procedure. Address data is included in the calculation of score values, among other factors, but not exclusively.

You may object to this processing of your data at any time by sending a message to us or directly to the provider. However, the provider may remain entitled to process your personal data where this is necessary for the contractual processing of payment.

8.5 We reserve the right to pass on your data to the debt collection service provider OKO Inkasso-Auskünfte GmbH & Co KG, Illweinstraße 30, 4020 Linz, in the event that our payment claim has not been settled despite a prior reminder. In such a case, the claim will be collected directly by the debt collection service provider.

The disclosure of your data serves the performance of the contract pursuant to Art. 6(1)(1)(b) GDPR and the protection of our legitimate interests, which prevail in a balancing of interests, in the effective enforcement of our payment claim pursuant to Art. 6(1)(1)(f) GDPR.

9) Web Analytics Services

9.1 Google (Universal) Analytics

This website uses Google (Universal) Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables the analysis of your use of our website.

By default, when you visit the website, Google (Universal) Analytics sets cookies — small text files placed on your device — which collect certain information. This information includes your IP address, which is however truncated by Google to exclude the last digits in order to prevent direct identification.

The information is transmitted to Google's servers and further processed there. Transmissions to Google LLC based in the USA are also possible.

Google uses the collected information on our behalf to evaluate your use of the website, to compile reports on website activity for us, and to provide other services related to website and internet usage. The truncated IP address transmitted by your browser within the context of Google Analytics is not merged with other data held by Google. Data collected through Google (Universal) Analytics is stored for a period of two months and then deleted.

All processing described above, in particular the placement of cookies on the device used, is only carried out if you have given us your express consent pursuant to Art. 6(1)(a) GDPR.
Without your consent, Google (Universal) Analytics will not be used during your visit to the site. You may withdraw your consent at any time with effect for the future. To exercise your right of withdrawal, please disable this service via the "Cookie Consent Tool" provided on the website.

We have entered into a data processing agreement with Google, which ensures the protection of our visitors' data and prohibits unauthorised disclosure to third parties.

Further legal information on Google (Universal) Analytics can be found at https://business.safety.google/intl/de/privacy/, https://policies.google.com/privacy?hl=de&gl=de and at https://policies.google.com/technologies/partner-sites

Demographic Features
Google (Universal) Analytics uses the special "demographic features" function, which can generate statistics about the age, gender and interests of website visitors. This is done by analysing advertising and information from third-party providers. This allows target groups to be identified for marketing activities. However, the data collected cannot be attributed to any specific individual and is deleted after being stored for a period of two months.

Google Signals
As an extension to Google (Universal) Analytics, Google Signals may be used on this website to generate cross-device reports. If you have enabled personalised ads and linked your devices to your Google Account, Google may — subject to your consent to the use of Google Analytics pursuant to Art. 6(1)(a) GDPR — analyse your usage behaviour across devices and create database models, including for cross-device conversions. We do not receive any personal data from Google, only statistics. If you wish to stop cross-device analysis, you can disable the "Personalised advertising" feature in your Google Account settings. Please follow the instructions on this page: https://support.google.com/My-Ad-Center-Help/answer/12155764?hl=de
Further information on Google Signals can be found at the following link: https://support.google.com/analytics/answer/7532985?hl=de

User IDs
As an extension to Google (Universal) Analytics, the "User IDs" feature may be used on this website. If you have consented to the use of Google (Universal) Analytics pursuant to Art. 6(1)(a) GDPR, have created an account on this website and log in to that account on different devices, your activities — including conversions — may be analysed across devices.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

9.2 Google Analytics 4

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables the analysis of your use of our website.

By default, when you visit the website, Google Analytics 4 sets cookies — small text files placed on your device — which collect certain information. This information includes your IP address, which is however truncated by Google to exclude the last digits in order to prevent direct identification.

The information is transmitted to Google's servers and further processed there. Transmissions to Google LLC based in the USA are also possible.

Google uses the collected information on our behalf to evaluate your use of the website, to compile reports on website activity for us, and to provide other services related to website and internet usage. The truncated IP address transmitted by your browser within the context of Google Analytics is not merged with other data held by Google. Data collected through Google Analytics 4 is stored for a period of two months and then deleted.

All processing described above, in particular the placement of cookies on the device used, is only carried out if you have given us your express consent pursuant to Art. 6(1)(a) GDPR.
Without your consent, Google Analytics 4 will not be used during your visit to the site. You may withdraw your consent at any time with effect for the future. To exercise your right of withdrawal, please disable this service via the "Cookie Consent Tool" provided on the website.

We have entered into a data processing agreement with Google, which ensures the protection of our visitors' data and prohibits unauthorised disclosure to third parties.

Further legal information on Google Analytics 4 can be found at https://business.safety.google/intl/de/privacy/, https://policies.google.com/privacy?hl=de&gl=de and at https://policies.google.com/technologies/partner-sites

Demographic Features
Google Analytics 4 uses the special "demographic features" function, which can generate statistics about the age, gender and interests of website visitors. This is done by analysing advertising and information from third-party providers. This allows target groups to be identified for marketing activities. However, the data collected cannot be attributed to any specific individual and is deleted after being stored for a period of two months.

Google Signals
As an extension to Google Analytics 4, Google Signals may be used on this website to generate cross-device reports. If you have enabled personalised ads and linked your devices to your Google Account, Google may — subject to your consent to the use of Google Analytics pursuant to Art. 6(1)(a) GDPR — analyse your usage behaviour across devices and create database models, including for cross-device conversions. We do not receive any personal data from Google, only statistics. If you wish to stop cross-device analysis, you can disable the "Personalised advertising" feature in your Google Account settings. Please follow the instructions on this page: https://support.google.com/My-Ad-Center-Help/answer/12155764?hl=de
Further information on Google Signals can be found at the following link: https://support.google.com/analytics/answer/7532985?hl=de

User IDs
As an extension to Google Analytics 4, the "User IDs" feature may be used on this website. If you have consented to the use of Google Analytics 4 pursuant to Art. 6(1)(a) GDPR, have created an account on this website and log in to that account on different devices, your activities — including conversions — may be analysed across devices.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

9.3 Google Tag Manager

This website uses "Google Tag Manager", a service provided by: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter "Google").

Google Tag Manager provides a technical foundation for bundling various web applications — including tracking and analytics services — and managing, calibrating and conditioning them through a unified interface. Google Tag Manager itself does not store or read information on users' devices, nor does it carry out independent data analysis. However, when a page is loaded, Google Tag Manager transmits your IP address to Google, where it may be stored. Transmission to servers of Google LLC in the USA is also possible.

This processing is only carried out if you have given us your express consent pursuant to Art. 6(1)(a) GDPR. Without such consent, Google Tag Manager will not be used during your visit to the site. You may withdraw your consent at any time with effect for the future. To exercise your withdrawal, please disable this service via the "Cookie Consent Tool" provided on the website.

We have entered into a data processing agreement with the provider, which ensures the protection of our visitors' data and prohibits unauthorised disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

Further legal information on Google Tag Manager can be found at https://business.safety.google/intl/de/privacy/ and https://policies.google.com/privacy?hl=de&gl=de

9.4 Microsoft Clarity

This website uses the web analytics service of the following provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.

Using cookies and/or comparable technologies (tracking pixels, web beacons, algorithms for reading device and browser information), the service collects and stores pseudonymised visitor data, including device information such as IP address and browser details, in order to evaluate it for statistical analysis of user behaviour on our website and to create pseudonymised usage profiles. Among other things, this enables the evaluation of movement patterns (so-called heatmaps), which show the duration of page visits and interactions with page content (e.g. text input, scrolling, clicks and mouse-overs). Pseudonymisation fundamentally excludes direct identification of individuals. The data is not merged with personal data collected by other means.

All processing described above, in particular the reading or storage of information on the device used, is only carried out if you have given us your express consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future by disabling this service via the "Cookie Consent Tool" provided on the website.

We have entered into a data processing agreement with the provider, which ensures the protection of our visitors' data and prohibits unauthorised disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

10) Retargeting / Remarketing and Conversion Tracking

10.1 Google Ads Remarketing

This website uses retargeting technology from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

For this purpose, Google places a cookie in your device's browser, which automatically enables interest-based advertising using a pseudonymous cookie ID based on the pages you have visited. Further data processing only takes place if you have agreed with Google that your internet and app browsing history is linked to your Google Account and information from your Google Account is used to personalise the ads you see on the web. If you are logged into Google while visiting our website in this case, Google uses your data together with Google Analytics data to create and define audience lists for cross-device remarketing. For this purpose, your personal data is temporarily linked by Google with Google Analytics data to form audiences. The use of Google Ads Remarketing may also result in the transfer of personal data to Google LLC's servers in the USA.

All processing described above, in particular the placement of cookies for reading information on the device used, is only carried out if you have given us your express consent pursuant to Art. 6(1)(a) GDPR. Without such consent, retargeting technology will not be used during your visit to the site.

You may withdraw your consent at any time with effect for the future. To exercise your withdrawal, please disable this service via the "Cookie Consent Tool" provided on the website.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

Details on the processing initiated by Google and on how Google handles data from websites can be found here: https://policies.google.com/technologies/partner-sites

Further information on Google's privacy policy can be found here: https://business.safety.google/intl/de/privacy/ and https://www.google.de/policies/privacy/

10.2 Microsoft Advertising

This website uses retargeting technology from the following provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.

This technology enables us to target visitors to our website with personalised, interest-based advertising who have already shown interest in our shop and products. The display of advertising is based on a cookie-based analysis of previous and current usage behaviour.

In the context of retargeting technology, a cookie is stored on your computer or mobile device to capture pseudonymised data about your interests and thereby tailor advertising to the stored information. These cookies are small text files stored on your computer or mobile device. You will be shown advertising that is highly likely to match your product and information interests.

All processing described above, in particular the placement of cookies for reading information on the device used, is only carried out if you have given us your express consent pursuant to Art. 6(1)(a) GDPR. Without such consent, retargeting technology will not be used during your visit to the site.

You may withdraw your consent at any time with effect for the future. To exercise your withdrawal, please disable this service via the "Cookie Consent Tool" provided on the website.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

10.3 billiger.de Sales Tracking

This website uses conversion tracking technology from the following provider: solute GmbH, Zeppelinstraße 15, D-76185 Karlsruhe, Germany.

If you arrived at our website via an advertisement on the provider's domain, the success of that advertisement can be tracked using cookies and/or comparable technologies (tracking pixels, web beacons, pings or HTTP requests).

For this purpose, certain device and browser information — potentially including your IP address — is read via the tracking technology in order to capture and evaluate predefined user actions (e.g. completed transactions, leads, search queries on the website, product page views). This enables the creation of statistics on user behaviour on our website following referral from an advertisement, which we use to optimise our offering.

All processing described above, in particular the placement of cookies for reading information on the device used, is only carried out if you have given us your express consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future by disabling this service via the "Cookie Consent Tool" provided on the website.

We have entered into a data processing agreement with the provider, which ensures the protection of our visitors' data and prohibits unauthorised disclosure to third parties.

10.4 Google Ads Conversion Tracking

This website uses the online advertising programme "Google Ads" and, as part of Google Ads, the conversion tracking service of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). We use Google Ads to draw attention to our attractive offers on external websites with the help of advertising materials (so-called Google Adwords). In relation to the advertising campaign data, we can determine how successful individual advertising measures are. Our aim is to show you advertising that is relevant to you, to make our website more interesting for you, and to achieve a fair calculation of advertising costs.

The conversion tracking cookie is set when a user clicks on a Google Ads advertisement. Cookies are small text files placed on your device. These cookies typically expire after 30 days and are not used for personal identification. When a user visits certain pages of this website and the cookie has not yet expired, Google and we can recognise that the user clicked on the advertisement and was redirected to that page. Each Google Ads customer receives a different cookie. Cookies therefore cannot be tracked across the websites of Google Ads customers. The information obtained through the conversion cookie is used to generate conversion statistics for Google Ads customers who have opted for conversion tracking. Customers learn the total number of users who clicked on their advertisement and were redirected to a page tagged with a conversion tracking tag. They do not, however, receive any information that could be used to personally identify users. The use of Google Ads may also result in the transfer of personal data to Google LLC's servers in the USA.

Details on the processing initiated by Google Ads Conversion Tracking and on how Google handles data from websites can be found here: https://policies.google.com/technologies/partner-sites

All processing described above, in particular the placement of cookies for reading information on the device used, is only carried out if you have given us your express consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future by disabling this service via the "Cookie Consent Tool" provided on the website.

You can also permanently object to the placement of cookies by Google Ads Conversion Tracking by downloading and installing the browser plug-in available at the following link:
https://support.google.com/My-Ad-Center-Help/answer/12155656?hl=de

Please note that certain features of this website may not be available or may only be available to a limited extent if you have disabled the use of cookies.
Google's privacy policy can be viewed here: https://business.safety.google/intl/de/privacy/ and https://www.google.de/policies/privacy/

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

10.5 Microsoft Advertising Universal Event Tracking

This website uses conversion tracking technology from the following provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.

For the use of Universal Event Tracking, a tag is embedded on every page of our website that interacts with the conversion cookie set by Microsoft. This interaction makes user behaviour on our website traceable and sends the information gathered to Microsoft. The purpose is to statistically record and evaluate predefined goals such as purchases or leads, in order to make the focus and content of our offerings more relevant to users' interests. The tags are never used for the personal identification of users.

All processing described above, in particular the placement of cookies for reading information on the device used, is only carried out if you have given us your express consent pursuant to Art. 6(1)(a) GDPR. Without such consent, retargeting technology will not be used during your visit to the site.

You may withdraw your consent at any time with effect for the future. To exercise your withdrawal, please disable this service via the "Cookie Consent Tool" provided on the website.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

11) Website Features

11.1 idealo Logo

Our website embeds graphic elements from the following provider for the purpose of displaying external customer reviews and/or an externally awarded quality seal: idealo internet GmbH, Zimmerstraße 50, 10888 Berlin, Germany.

When you access a page on our website that contains such graphic elements, your browser establishes a direct connection to the provider's servers in order to load the elements correctly. In doing so, certain browser information, including your IP address, is transmitted to the provider.

Where personal data is processed in this context, this is done pursuant to Art. 6(1)(f) GDPR on the basis of our legitimate interest in the optimal marketing of our offering and the appealing presentation of our website.

11.2 Trusted Shops Trustbadge

Our website embeds graphic elements from the following provider for the purpose of displaying external customer reviews and/or an externally awarded quality seal: Trusted Shops AG, Subbelrather Str. 15C, 50823 Cologne, Germany.

When you access a page on our website that contains such graphic elements, your browser establishes a direct connection to the provider's servers in order to load the elements correctly. In doing so, certain browser information, including your IP address, is transmitted to the provider.

Where personal data is processed in this context, this is done pursuant to Art. 6(1)(f) GDPR on the basis of our legitimate interest in the optimal marketing of our offering and the appealing presentation of our website.

In the event of an online order with us, further processing may take place.

Depending on your express consent pursuant to Art. 6(1)(a) GDPR, your order information (order total, order number, and where applicable the purchased product) as well as your email address will be transmitted in encrypted form to the provider via the Trustbadge after an order is completed, in order to verify whether you are already registered for the provider's services (in particular the "Buyer Protection") and, if applicable, to enable new registration.

In the event that an existing registration is identified or in the event of a new registration with the provider for its services (in particular the Buyer Protection), your order information (order total, order number, purchased product) and your email address will be transmitted to the provider and further processed by the provider pursuant to Art. 6(1)(b) GDPR on the basis of the contractual agreement with the provider, in order to provide the services (in particular the Buyer Protection).

We are jointly responsible with the provider for the processing described above pursuant to Art. 26 GDPR. The joint controllership agreement can be viewed here: https://help.etrusted.com/hc/de/articles/23970817960082

11.3 Google reCAPTCHA

This website uses the CAPTCHA service of the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

Data may also be transmitted to: Google LLC, USA.

The provider uses "Google Fonts" — fonts loaded from the internet by Google — for the visual design of the CAPTCHA window. No further information beyond that already transmitted to Google through the reCAPTCHA functionality is processed in this context.

The service verifies whether input is made by a natural person or abusively through automated processing, and blocks spam, DDoS attacks and similar automated malicious access. To ensure that an action is performed by a human and not an automated bot, the provider collects the IP address of the device used, identification data of the browser and operating system type used, and the date and duration of the visit, and transmits this data to the provider's servers for evaluation. Cookies — small text files stored in the device's browser — may be used in this process.

Where the processing described above is based on cookies, these are only placed if you have given us your express consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future by disabling this service via the "Cookie Consent Tool" provided on the website.

Where the processing described above is carried out without the use of cookies, the legal basis is our legitimate interest in establishing individual accountability on the internet and preventing misuse and spam pursuant to Art. 6(1)(f) GDPR.

We have entered into a data processing agreement with the provider, which ensures the protection of our visitors' data and prohibits unauthorised disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

12) Tools and Miscellaneous

Cookie Consent Tool

This website uses a so-called "Cookie Consent Tool" to obtain valid user consent for cookies and cookie-based applications that require consent. The "Cookie Consent Tool" is displayed to users when the page is loaded in the form of an interactive interface, through which consent for specific cookies and/or cookie-based applications can be granted by ticking the relevant boxes. By using this tool, all cookies/services requiring consent are only loaded if the respective user has granted the appropriate consent by ticking the boxes. This ensures that such cookies are only placed on the user's device once consent has been given.

The tool places technically necessary cookies to store your cookie preferences. Personal user data is generally not processed in this context.

In individual cases where personal data (such as an IP address) is processed for the purpose of storing, assigning or logging cookie settings, this is done pursuant to Art. 6(1)(f) GDPR on the basis of our legitimate interest in lawful, user-specific and user-friendly consent management for cookies and therefore in the legally compliant design of our website.

A further legal basis for processing is Art. 6(1)(c) GDPR. As the controller, we are subject to the legal obligation to make the use of technically non-essential cookies conditional on the respective user's consent.

Where required, we have entered into a data processing agreement with the provider, which ensures the protection of our visitors' data and prohibits unauthorised disclosure to third parties.

Further information about the operator and the settings of the Cookie Consent Tool can be found directly in the corresponding interface on our website.

13) Data Subject Rights

13.1 Applicable data protection law grants you the following data subject rights (rights to information and intervention) with respect to the processing of your personal data by the controller, subject to the respective conditions for their exercise as set out in the referenced legal provisions:

  • Right of access pursuant to Art. 15 GDPR;
  • Right to rectification pursuant to Art. 16 GDPR;
  • Right to erasure pursuant to Art. 17 GDPR;
  • Right to restriction of processing pursuant to Art. 18 GDPR;
  • Right to notification pursuant to Art. 19 GDPR;
  • Right to data portability pursuant to Art. 20 GDPR;
  • Right to withdraw consent pursuant to Art. 7(3) GDPR;
  • Right to lodge a complaint pursuant to Art. 77 GDPR.

13.2 RIGHT TO OBJECT

WHERE WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF A BALANCING OF INTERESTS IN ACCORDANCE WITH OUR OVERRIDING LEGITIMATE INTEREST, YOU HAVE THE RIGHT TO OBJECT TO SUCH PROCESSING AT ANY TIME WITH EFFECT FOR THE FUTURE, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED. HOWEVER, CONTINUED PROCESSING REMAINS POSSIBLE IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR IF THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS.

WHERE YOUR PERSONAL DATA IS PROCESSED BY US FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSES OF SUCH MARKETING. YOU MAY EXERCISE THE OBJECTION AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.

14) Duration of Storage of Personal Data

The duration of storage of personal data is determined by the applicable legal basis, the purpose of processing and — where relevant — additionally by the applicable statutory retention period (e.g. commercial and tax law retention periods).

When processing personal data on the basis of express consent pursuant to Art. 6(1)(a) GDPR, the data concerned is stored until you withdraw your consent.

Where statutory retention periods exist for data processed in the context of contractual or quasi-contractual obligations on the basis of Art. 6(1)(b) GDPR, such data is routinely deleted after the expiry of the retention periods, provided it is no longer necessary for the performance or initiation of a contract and/or we have no legitimate interest in continued storage.

When processing personal data on the basis of Art. 6(1)(f) GDPR, such data is stored until you exercise your right to object pursuant to Art. 21(1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

When processing personal data for the purpose of direct marketing on the basis of Art. 6(1)(f) GDPR, such data is stored until you exercise your right to object pursuant to Art. 21(2) GDPR.

Unless otherwise stated in the other information in this statement regarding specific processing situations, stored personal data will be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.