Privacy Policy
1. General Data Protection
General Information
The following information provides a simple overview of what happens to your personal data, for example, when you visit this website. Personal data is any data that can be used to personally identify you. For detailed information on data protection, please refer to our Privacy Policy, which is listed below this text.
1.1. Data Controller and Contact Information
Unless otherwise specified in individual cases, Original Food GmbH is responsible for the data processing described here. Inquiries regarding data protection may be sent to us by mail or email, accompanied by a copy of the user’s ID or passport for identification purposes.
The entity responsible for data processing on this website is:
Original Food GmbH
Sonnenbühlweg
6010 Kriens / LU
Switzerland
Phone: +41 41 630 14 01
Email: office@originalfood.ch
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g., names, email addresses, etc.).
1.2. Collection and Processing of Personal Data
We process personal data, particularly in the following categories:
- Customer data from customers for whom we provide or have provided services.
- Personal data that we have received indirectly from our customers in the course of providing our services.
- When visiting our website
- When using our newsletter
- When you attend one of our events.
- When we communicate or when someone visits.
- In the case of other contractual relationships, such as as a supplier, service provider, or consultant.
- When applying
- If we are required to do so for legal or regulatory reasons.
- When we exercise our due diligence obligations or other legitimate interests, such as to avoid conflicts of interest, prevent money laundering or other risks, ensure data accuracy, verify creditworthiness, ensure security, or enforce our rights.
1.3. Categories of Personal Data
We collect the following categories of personal data, depending on the purpose for which we process them:
- Contact information (e.g., last name, first name, address, phone number, email)
- Customer information (e.g., date of birth, nationality, marital status, occupation, title, job title, passport/ID number, AHV number)
- Risk assessment data (e.g., creditworthiness information, commercial registry data)
- Financial information (e.g., bank account information)
- Website data (e.g., IP address, device information (UDI), browser information, website usage (analytics and use of plugins, etc.))
- Application materials (e.g., resume, employment references)
- Marketing information (e.g., newsletter subscription)
- Security and network data (e.g., visitor logs, access controls, network and email scanners, phone call logs)
1.4. Purposes of Data Processing and Legal Basis
Provision of Services
We primarily process the personal data that we receive from our customers in the course of our business relationships with them, as well as from business partners and other individuals involved in such relationships.
Our customers' personal data consists, in particular, of the following information:
- Contact information (e.g., last name, first name, address, phone number, email, other contact information)
- Personal information (e.g., date of birth, nationality, marital status, occupation, title, job title, passport/ID number, AHV number, family circumstances, etc.)
- Risk assessment data (e.g., creditworthiness information, commercial registry data, sanctions lists, specialized databases, data from the Internet)
- Financial information (e.g., bank account information, investments, or equity interests)
We process this personal data for the purposes described based on the following legal grounds:
- Conclusion or performance of a contract with the data subject or for the benefit of the data subject, including contract negotiations and any enforcement
- Compliance with a legal obligation (e.g., when we are required to disclose information)
- Protection of legitimate interests (e.g., for administrative purposes, to improve our quality, ensure security, conduct risk management, enforce our rights, defend ourselves against claims, or to assess potential conflicts of interest)
- Consent (e.g., to send you marketing information).
1.5. Indirect Data Processing in Connection with the Provision of Services
When we provide services to our customers, we may also process personal data that we did not collect directly from the data subjects, or personal data from third parties. These third parties are generally employees, contacts, family members, or individuals who have a relationship with the customers or the data subjects for other reasons. We need this personal data to fulfill contracts with our customers. We receive this personal data from our clients or from third parties commissioned by our clients. Third parties whose information we process for this purpose are informed by our clients that we are processing their data. Our clients may refer to this Privacy Policy for this purpose.
The personal data of individuals who have a relationship with our customers includes, in particular, the following information:
- Contact information (e.g., last name, first name, address, phone number, email, other contact information, marketing data)
- Personal information (e.g., date of birth, nationality, marital status, occupation, title, job title, passport/ID number, AHV number, family circumstances, etc.)
- Financial information (e.g., bank account information, investments, or equity interests)
- Sensitive personal data: This personal data may also include sensitive personal data, such as data regarding health, religious beliefs, or social assistance measures, particularly when we provide payroll processing or accounting services.
We process this personal data for the purposes described based on the following legal grounds:
- Entering into or performing a contract with the data subject or for the benefit of the data subject (e.g., when we fulfill our contractual obligations)
- Compliance with a legal obligation (e.g., when we are fulfilling our duties as auditors or are required to disclose information)
- Protection of legitimate interests, in particular our interest in providing optimal service to our customers.
1.6. Participation in Events
If you participate in an event organized by us, we collect personal data in order to organize and conduct the event and, if applicable, to send you additional information afterward. We also use your information to notify you of other events. We may take photographs or film you at these events and publish this visual material internally or externally.
This includes, in particular, the following information:
- Contact information (e.g., last name, first name, address, phone number, email)
- Personal information (e.g., occupation, position, title, employer, eating habits)
- Pictures or videos
- Payment information (e.g., bank account information).
We process this personal data for the purposes described based on the following legal grounds:
- Fulfillment of a contractual obligation with or for the benefit of the data subject, including contract initiation and, if necessary, enforcement (enabling participation in the event)
- Protection of legitimate interests (e.g., hosting events, disseminating information about our event, providing services, efficient organization)
- Consent (e.g., to send you marketing information or to create visual content).
1.7. Direct Communication and Visits
When you contact us (e.g., by phone, email, or chat) or we contact you, we process the personal data necessary for that purpose. We also process this personal data when you visit us. In this case, you may be asked to provide your contact information before your visit or at the reception desk. We retain this information for a certain period of time to protect our infrastructure and our information.
We use the “Zoom” or “Microsoft Teams” services to conduct conference calls, online meetings, video conferences, and/or webinars (“online meetings”).
In particular, we process the following information:
- Contact information (e.g., last name, first name, address, phone number, email)
- Communication metadata (e.g., IP address, duration of communication, communication channel)
- Recordings of conversations, e.g., during video conferences
- Other information that the user uploads, provides, or creates while using the video conferencing service, as well as metadata used for the maintenance of the service. Additional information regarding the processing of personal data by “Zoom” or Microsoft Teams can be found in their respective privacy policies.
- Personal information (e.g., occupation, position, title, employer)
- Date and reason for the visit.
We process this personal data for the purposes described based on the following legal grounds:
- Fulfillment of a contractual obligation with or for the benefit of the data subject, including contract initiation and, if necessary, enforcement (provision of a service)
- Protection of legitimate interests (e.g., security, traceability, and the management and administration of customer relationships).
1.8. Applications
You can submit your application for a position with us by mail or via the email address listed on our website. Your application materials and all personal data provided to us in connection therewith will be treated as strictly confidential, will not be disclosed to any third party, and will be processed solely for the purpose of reviewing your application for employment with us. Unless you consent otherwise, your application materials will be either returned to you or deleted/destroyed upon completion of the application process, provided they are not subject to a statutory retention requirement. The legal basis for processing your data is your consent, the performance of the contract with you, and our legitimate interests.
In particular, we process the following information:
- Contact information (e.g., last name, first name, address, phone number, email)
- Personal information (e.g., occupation, position, title, employer)
- Application materials (e.g., letter of motivation, transcripts, diplomas, resume)
- Evaluation information (e.g., HR consultant evaluations, reference checks, assessments)
We process this personal data for the purposes described based on the following legal grounds:
- Protection of legitimate interests (e.g., hiring new employees)
- Consent.
1.9. Suppliers, Service Providers, and Other Contractual Partners
When we enter into a contract with you for you to provide a service to us, we process personal data about you or your employees. We need this data to communicate with you and to utilize your services. We may also process this personal data to assess whether a conflict of interest might exist and to ensure that our collaboration does not expose us to any unintended risks, such as those related to money laundering or sanctions.
In particular, we process the following information:
- Contact information (e.g., last name, first name, address, phone number, email).
- Personal information (e.g., occupation, position, title, employer).
- Financial information (e.g., bank account information).
We process this personal data for the purposes described based on the following legal grounds:
- Conclusion or performance of a contract with the data subject or for the benefit of the data subject, including contract negotiations and any enforcement
- Protection of legitimate interests (e.g., avoiding conflicts of interest, protecting the company, enforcing legal claims).
1.10. Data Sharing and Data Transfer
We will only disclose your data to third parties if it is necessary to provide our services, if these third parties provide a service on our behalf, if we are required to do so by law or by a government agency, or if we have an overriding interest in disclosing the personal data. We will also disclose personal data to third parties if you have given your consent or have requested that we do so.
Not all personal data is transmitted in encrypted form by default. Unless otherwise explicitly agreed upon with the customer, accounting data, payroll administration data, pay stubs, and payroll statements are transmitted in unencrypted form.
The following categories of recipients may receive personal data from us:
-
- Service providers (e.g., IT service providers, hosting providers, suppliers, consultants, attorneys, insurance companies).
- Third parties in connection with our legal or contractual obligations, government agencies, public institutions, and courts.
We enter into contracts with service providers who process personal data on our behalf, obligating them to ensure data protection. The majority of our service providers are located in Switzerland or in the EU/EEA. Certain personal data may also be transferred to the United States (e.g., Google Analytics data) or, in exceptional cases, to other countries worldwide. If a data transfer to other countries that do not have an adequate level of data protection is necessary, it will be carried out on the basis of the EU Standard Contractual Clauses (e.g., in the case of Google) or other suitable instruments.
1.11. Retention Period for Personal Data
We process and store your personal data for as long as necessary to fulfill our contractual and legal obligations or to achieve the purposes for which the data is processed; that is, for example, for the duration of the entire business relationship (from the initiation and execution of a contract through to its termination) and beyond, in accordance with statutory retention and documentation requirements. In this context, personal data may be retained for the period during which claims against our company may be asserted (i.e., in particular, during the statutory limitation period) and to the extent that we are otherwise legally obligated to do so or legitimate business interests require it (e.g., for evidentiary and documentation purposes). As soon as your personal data is no longer required for the purposes mentioned above, it will generally be deleted or anonymized to the extent possible. For operational data (e.g., system logs), shorter retention periods of twelve months or less generally apply.
1.12. Data Security
We implement appropriate technical and organizational security measures to protect your personal data from unauthorized access and misuse, such as issuing guidelines, providing training, implementing IT and network security solutions, establishing access controls and restrictions, encrypting data storage media and data transmissions, pseudonymizing data, and conducting audits.
1.13. Obligation to Provide Personal Data
As part of our business relationship, you must provide the personal data necessary for establishing and conducting a business relationship and for fulfilling the associated contractual obligations (you are generally not legally required to provide us with data). Without this data, we will not be able to enter into or fulfill a contract with you (or the entity or person you represent). Furthermore, the website cannot be used if certain information required to ensure data transmission (such as your IP address) is not disclosed.
1.14. Your Rights
You have the following rights regarding our processing of personal data:
- The right to access the personal data we have stored about you, the purpose of the processing, the source of the data, and the recipients or categories of recipients to whom the personal data is disclosed.
- Right to rectification if your data is incorrect or incomplete.
- Right to Restrict the Processing of Your Personal Data
- The right to request the deletion of processed personal data
- Right to Data Portability
- The right to object to the processing of data or to withdraw consent to the processing of personal data at any time without providing a reason.
- The right to file a complaint with a competent supervisory authority, where provided for by law.
To exercise these rights, please contact us at the address provided in Section 1.
Please note, however, that we reserve the right to invoke the restrictions provided for by law, for example, if we are required to retain or process certain data, have an overriding interest in doing so (to the extent we are permitted to invoke such an interest), or need the data to assert claims. If you incur any costs, we will inform you in advance.
2. Data Protection When Using Our Website: At a Glance
Data Collection on This Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. See above.
How do we collect your data?
Your data is collected, in part, when you provide it to us. This may include, for example, data that you enter into a contact form.
Other data is collected by our IT systems automatically or with your consent when you visit the website. This primarily consists of technical data (e.g., internet browser, operating system, or the time the page was accessed). This data is collected automatically as soon as you access this website.
What do we use your data for?
Some of the data is collected to ensure that the website functions properly. Other data may be used to analyze your user behavior.
Analytics Tools and Third-Party Tools
When you visit this website, your browsing behavior may be analyzed for statistical purposes. This is primarily done using so-called analytics tools.
You can find detailed information about these analytics programs in the following privacy policy.
3. Hosting Our Website
We host our website's content with the following provider:
External Hosting
This website is hosted externally. The personal data collected on this website is stored on the host’s servers. This may include, in particular, IP addresses, contact requests, metadata and communication data, contract data, contact information, names, website visits, and other data generated through a website.
External hosting is carried out for the purpose of fulfilling our contractual obligations to our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of ensuring the secure, fast, and efficient provision of our online services by a professional provider (Art. 6(1)(f) GDPR). If consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent may be revoked at any time.
Our hosting provider(s) will process your data only to the extent necessary to fulfill its service obligations and will follow our instructions regarding this data.
We use the following hosting provider(s):
Hostpoint AG
Neue Jonastrasse 60
8640 Rapperswil-Jona
Switzerland
Order Processing
We have entered into a Data Processing Agreement (DPA) for the use of the aforementioned service. This is a contract required under data protection law that ensures the service provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the DSG and the GDPR.
4. General Information and Mandatory Disclosures Regarding Data Protection on Our Website
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with applicable data protection laws and this Privacy Policy.
When you use this website, various types of personal data are collected. Personal data is information that can be used to personally identify you at
. This Privacy Policy explains what data we collect and how we use it. It also explains how and for what purpose this is done.
Please note that data transmission over the Internet (e.g., when communicating via email) may be subject to security vulnerabilities. It is not possible to completely protect data from access by third parties.
General Information on the Legal Basis for Data Processing on This Website
If you have consented to the processing of your data, we process your personal data on the basis of Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, provided that special categories of data as defined in Article 9(1) of the GDPR are being processed. In the event of explicit consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Article 49(1)(a) of the GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g., via device fingerprinting), data processing is additionally carried out on the basis of Section 25(1) of the German Teleservices Data Protection Act (TTDSG). Consent may be revoked at any time. If your data is necessary for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Article 6(1)(b) of the GDPR. Furthermore, we process your data if it is necessary to comply with a legal obligation on the basis of Article 6(1)(c) of the GDPR. Data processing may also be based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR. The applicable legal bases in each individual case are described in the following sections of this Privacy Policy.
Notice Regarding the Transfer of Data to Third Countries That Do Not Meet Data Protection Standards, as Well as the Transfer of Data to U.S. Companies That Are Not DPF-Certified
Among other things, we use tools from companies based in third countries that do not meet EU data protection standards, as well as U.S. tools whose providers are not certified under the EU-U.S. Data Privacy Framework (DPF). When these tools are active, your personal data may be transferred to and processed in these countries. Please note that third countries that do not meet EU data protection standards cannot guarantee a level of data protection comparable to that of the EU.
Please note that the United States, as a safe third country, generally maintains a level of data protection comparable to that of the EU and Switzerland. Data transfers to the United States are therefore permitted if the recipient is certified under the “EU-US Data Privacy Framework” (DPF) or has appropriate additional safeguards in place. Information regarding transfers to third countries, including the recipients of the data, can be found in this Privacy Policy.
Recipients of personal data
As part of our business operations, we collaborate with various external parties. In some cases, this requires the transfer of personal data to these external parties. We only disclose personal data to external parties if this is necessary for the performance of a contract, if we are legally obligated to do so (e.g., disclosure of data to tax authorities), if we have a legitimate interest in the disclosure pursuant to Article 6(1)(f) of the GDPR, or if another legal basis permits the disclosure of data. When using data processors, we only disclose our customers’ personal data on the basis of a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.
Withdrawal of Your Consent to Data Processing
Many data processing operations are only possible with your explicit consent. You may withdraw any consent you have already given at any time. The lawfulness of the data processing carried out prior to the withdrawal remains unaffected by the withdrawal.
Right to object to data collection in specific cases and to direct marketing (Art. 21 GDPR)
IF DATA PROCESSING IS BASED ON ART. 6, PAR. 1, SUBPAR. E OR F OF THE GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. YOU CAN FIND THE SPECIFIC LEGAL BASIS ON WHICH PROCESSING IS BASED IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA, UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, exercise, or defense of legal claims (objection pursuant to Art. 21(1) of the GDPR).
IF YOUR PERSONAL DATA IS BEING PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING PURPOSES; THIS ALSO APPLIES TO PROFILING, TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR THE PURPOSES OF DIRECT MARKETING (OBJECTION PURSUANT TO ART. 21(2) OF THE GDPR).
Right to File a Complaint with the Competent Supervisory Authority
In the event of violations of the DSG and the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the location of the alleged violation. This right to lodge a complaint is without prejudice to other administrative or judicial remedies.
Right to Data Portability
You have the right to have data that we process automatically—based on your consent or in fulfillment of a contract—provided to you or to a third party at
in a commonly used, machine-readable format. If you request the direct transfer of the data to another data controller, this will be done only to the extent that it is technically feasible.
Access, Correction, and Deletion
In accordance with applicable legal provisions, you have the right at any time to receive, free of charge, information about your stored personal data, its origin and recipients, and the purpose of the data processing, as well as the right to have this data corrected or deleted, if applicable. You may contact us at any time regarding this matter or any other questions you may have about personal data.
Right to Restriction of Processing
You have the right to request that the processing of your personal data be restricted. You can contact us at any time to do so.
The right to restriction of processing applies in the following cases:
If you dispute the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of the verification, you have the right to request that the processing of your personal data be restricted.
If the processing of your personal data was or is unlawful, you may request that the processing be restricted instead of having the data erased.
If we no longer need your personal data, but you need it to exercise, defend, or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of erasure.
If you have lodged an objection pursuant to Art. 21(1) of the GDPR, a balancing of your interests against ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, such data—apart from its storage—may be processed only with your consent, or for the purpose of asserting, exercising, or defending legal claims, or to protect the rights of another natural or legal person, or for reasons of an important public interest of the European Union or a Member State.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential information—such as orders or inquiries that you send to us, the operator of
—this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the browser’s address bar changes from “http://” to “https://” and by the padlock icon in your browser’s address bar.
If SSL or TLS encryption is enabled, the data you send to us cannot be read by third parties.
5. Data Collection on This Website
5.1. Cookies
Our website uses so-called “cookies.” Cookies are small data packets that do not cause any damage to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted at the end of your visit. Persistent cookies remain stored on your device until you delete them yourself or your web browser deletes them automatically.
Cookies may be set by us (first-party cookies) or by third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain third-party services into websites (e.g., cookies used to process payment services).
Cookies serve various purposes. Many cookies are technically necessary, as certain website features would not work without them (e.g., the shopping cart feature or the display of videos). Other cookies may be used to analyze user behavior or for advertising purposes.
Cookies that are necessary for carrying out the electronic communication process, for providing certain functions you have requested on
(e.g., the shopping cart function), or for optimizing the website (e.g., cookies for measuring web traffic) (necessary cookies), are stored on the basis of Art. 6(1)(f) of the GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies to ensure the technically error-free and optimized provision of its services. If consent to the storage of cookies and similar tracking technologies has been requested, processing is carried out exclusively on the basis of this consent (Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG); consent may be revoked at any time.
You can configure your browser to notify you when cookies are set and to allow cookies only on a case-by-case basis, to block cookies in certain cases or generally, and to enable the automatic deletion of cookies when you close your browser. Disabling cookies may limit the functionality of this website.
You can find out which cookies and services are used on this website in this Privacy Policy.
5.2. Server Log Files
The provider of this website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These include:
- Browser Type and Browser Version
- Operating system used
- Referrer URL
- Hostname of the connecting computer
- Time of the server request
- IP address
This data is not combined with data from other sources.
This data is collected on the basis of Article 6(1)(f) of the GDPR. The website operator has a legitimate interest in ensuring that its website functions properly and is optimized—to this end, server log files must be collected.
5.3. Contact Form
If you submit inquiries to us via the contact form, we will store the information you provide in the inquiry form—including the contact information you provide there—for the purpose of processing your inquiry and in case of follow-up questions. We will not share this data without your consent.
This data is processed on the basis of Article 6(1)(b) of the GDPR, provided that your inquiry is related to the performance of a contract or is necessary for the implementation of precontractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries directed to us (Article 6(1)(f) of the GDPR) or on your consent (Article 6(1)(a) of the GDPR), provided that consent was requested; consent may be withdrawn at any time.
The data you enter in the contact form will remain with us until you request that we delete it, revoke your consent to its storage, or the purpose for storing the data no longer applies (e.g., after your inquiry has been processed). Mandatory legal provisions—in particular retention periods—remain unaffected.
6. Newsletter
Newsletter Information
If you would like to subscribe to the newsletter offered on the website, we need your email address as well as information that allows us to verify that you are the owner of the provided email address and that you consent to receiving the newsletter. No other data is collected, or is collected only on a voluntary basis. We use this data exclusively to send you the requested information and do not share it with third parties at
.
The processing of the data entered in the newsletter sign-up form is based solely on your consent (Art. 6(1)(a) GDPR). You may revoke your consent to the storage of your data and email address, as well as their use for sending the newsletter, at any time—for example, by clicking the “Unsubscribe” link in the newsletter. The lawfulness of data processing operations that have already taken place remains unaffected by this revocation
.
The data you have provided to us for the purpose of subscribing to the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter, and will be deleted from the newsletter distribution list after you unsubscribe or once the purpose for which it was collected no longer applies. We reserve the right to delete or block email addresses from our newsletter distribution list at our sole discretion within the scope of our legitimate interest pursuant to Article 6(1)(f) of the GDPR.
Data that we have stored for other purposes is not affected by this.
After you unsubscribe from the newsletter mailing list, your email address may be stored in a blacklist by us or the newsletter service provider, if necessary, to prevent future mailings. The data from the blacklist is used solely for this purpose and is not combined with any other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Article 6(1)(f) of the GDPR). There is no time limit on storage in the blacklist. You may object to this storage if your interests outweigh our legitimate interest.
7. Plugins and Tools
7.1. YouTube
This website embeds videos from YouTube. The website is operated by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit one of our web pages that includes a YouTube video, a connection is established with YouTube's servers. In the process, the YouTube server is informed which of our pages you have visited.
In addition, YouTube may store various cookies on your device or use similar technologies for identification purposes (e.g., device fingerprinting). This allows YouTube to obtain information about visitors to this website. This information is used, among other things, to collect video statistics, improve the user experience, and prevent fraud.
If you are logged in to your YouTube account, you are allowing YouTube to associate your browsing activity directly with your personal profile. You can prevent this by logging out of your YouTube account.
We use YouTube to ensure that our online offerings are presented in an appealing manner. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the GDPR. If consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent may be revoked at any time.
For more information on how user data is handled, please see YouTube's Privacy Policy at: https://policies.google.com/privacy?hl=de.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards when data is processed in the United States. Every company certified under the DPF commits to complying with these data protection standards. For more information on this, please visit the provider’s website at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
7.2. Vimeo
This website uses plugins from the video portal Vimeo. The provider is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.
When you visit one of our pages that contains a Vimeo video, a connection is established with Vimeo’s servers. In the process, the Vimeo server at
is informed which of our pages you have visited. Vimeo also obtains your IP address. This applies even if you are not logged in to Vimeo or do not have a Vimeo account. The information collected by Vimeo is transmitted to Vimeo’s servers in the United States.
When you are logged in to your Vimeo account, you allow Vimeo to associate your browsing activity directly with your personal profile. You can prevent this by logging out of your Vimeo account.
Vimeo uses cookies or similar tracking technologies (e.g., device fingerprinting) to recognize website visitors.
We use Vimeo to ensure that our online content is presented in an appealing manner. This constitutes a legitimate interest within the meaning of
Article 6(1)(f) of the GDPR. If consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s device
(e.g., device fingerprinting) within the meaning of the TTDSG. Consent may be revoked at any time.
Data transfers to the United States are based on the European Commission’s Standard Contractual Clauses and, according to Vimeo, on “legitimate business interests.” For details, see here: https://vimeo.com/privacy.
For more information on how user data is handled, please see Vimeo's Privacy Policy at: https://vimeo.com/privacy.
7.3. Google Fonts
This site uses Google Fonts, provided by Google, to ensure consistent font display. When you visit a page, your browser loads the necessary fonts into its cache to display text and fonts correctly.
To this end, the browser you are using must establish a connection to Google’s servers. As a result, Google becomes aware that this website has been accessed via your IP address. The use of Google Fonts is based on Article 6(1)(f) of the GDPR. The website operator has a legitimate interest in ensuring a consistent font appearance on its website. If consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent may be revoked at any time.
If your browser does not support Google Fonts, a default font from your computer will be used.
For more information about Google Fonts, visit https://developers.google.com/fonts/faq and see Google's Privacy Policy: https://policies.google.com/privacy?hl=de.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards when data is processed in the United States. Every company certified under the DPF commits to complying with these data protection standards. For more information on this, please visit the provider’s website at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
7.4. Google reCAPTCHA
We use “Google reCAPTCHA” (hereinafter “reCAPTCHA”) on this website. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA is used to verify whether data entry on this website (e.g., in a contact form) is performed by a human or by an automated program. To do this, reCAPTCHA analyzes the website visitor’s behavior based on various characteristics. This analysis begins automatically as soon as the website visitor accesses the website. For the analysis, reCAPTCHA evaluates various pieces of information (e.g., IP address, the length of time the website visitor spends on the website, or the user’s mouse movements). The data collected during the analysis is forwarded to Google.
reCAPTCHA analyses run entirely in the background. Website visitors are not notified that an analysis is taking place.
The storage and analysis of the data are based on Article 6(1)(f) of the GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated surveillance and from spam. If consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent may be revoked at any time.
For more information about Google reCAPTCHA, please refer to Google's Privacy Policy and Terms of Service at the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards when data is processed in the United States. Every company certified under the DPF commits to complying with these data protection standards. For more information on this, please visit the provider’s website at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
7.5. Wordfence
We have integrated Wordfence into this website. The provider is Defiant Inc., Defiant, Inc., 800 5th Ave Ste 4100, Seattle, WA 98104, USA (hereinafter “Wordfence”).
Wordfence is used to protect our website from unauthorized access or malicious cyberattacks. To this end, our website establishes a persistent connection to Wordfence’s servers so that Wordfence can compare the access attempts made on our website against its databases and block them if necessary.
The use of Wordfence is based on Article 6(1)(f) of the GDPR.
The website operator has a legitimate interest in protecting its website as effectively as possible against cyberattacks. If consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, provided that the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) as defined by the TTDSG. Consent may be revoked at any time.
Data transfers to the United States are based on the European Commission's Standard Contractual Clauses. For details, please visit: https://www.wordfence.com/help/general-data-protection-regulation/.
Order Processing
We have entered into a Data Processing Agreement (DPA) for the use of the aforementioned service. This is a contract required under data protection law that ensures the service provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the DSG and the GDPR.
7.6. Social Media
Our website uses so-called social media plugins (“plugins”) from third-party providers. The plugins can be identified by the logo of the respective social network. Through these plugins, we offer you the opportunity to interact with social networks and other users. When you visit our website, your browser establishes a direct connection to the third-party provider’s servers. The content of the plugin (e.g., YouTube videos) is transmitted directly from the respective third-party provider to your browser and integrated into the page.
Data is shared for the purpose of displaying content (e.g., posts on Twitter) regardless of whether you have an account with the third-party provider and are logged in there. If you are logged in with the third-party provider, the data we collect about you will also be directly linked to your existing account with that provider. If you activate the plugins, the information will also be published on the social network and displayed there to your contacts. For information on the purpose and scope of data collection, as well as the further processing and use of the data by the third-party providers, and your rights and privacy settings in this regard, please refer to the third-party providers’ privacy policies. The third-party provider stores the data collected about you as user profiles and uses this data for advertising, market research, and/or to tailor its website to your needs. Such analysis is carried out in particular for users who are not logged in, to display targeted advertising and to inform other users of the social network about your activities on our website. If you wish to prevent third-party providers from linking the data collected via our website to your personal profile on the respective social network, you must log out of the relevant social network before visiting our website. You can also completely prevent the plugins from loading by using specialized browser add-ons such as “Ghostery” (https://www.ghostery.com/) or “NoScript” (http://noscript.net/).
7.7. WooCommerce
WooCommerce is an open-source e-commerce platform. It is based on the WordPress content management system, which is a subsidiary of Automattic Inc. (60 29th Street #343, San Francisco, CA 94110, USA). Through the implemented features, data is sent to, stored by, and processed by Automattic Inc.
Why do we use WooCommerce?
We use this convenient online store solution to offer you our products and services in the best possible way on our website. Our goal is to provide you with simple and easy access to our offerings so that you can find the products you want quickly and easily.
8. Changes to the Privacy Policy
We expressly reserve the right to amend this Privacy Policy at any time.
Last updated: September 2023
