PRIVACY POLICY
Privacy Policy
We are delighted that you are visiting our website. The protection and security of your personal information when using our website is very important to us. We would therefore like to take this opportunity to inform you about which of your personal data we collect when you visit our website and for what purposes it is used. Personal data refers to specific details regarding the personal or factual circumstances of an identified or identifiable natural person (data subject), e.g. name, address, email addresses, user behaviour. This therefore refers to data that enables us to identify you. In addition, you will also find some information here regarding data processing activities outside this website (e.g. video conferences or newsletters).
Responsible for data processing
Data controller
For the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR)
Hargesheimer Kunstauktionen Düsseldorf GmbH
Friedrich-Ebert-Strasse 11+12
40210 Düsseldorf
Telephone: +49 (0) 211 – 30 200 10
Email:info@kunstauktionen-duesseldorf.de
Data Protection Officer
exkulpa gmbh
Waldfeuchterstr. 266
52525 Heinsberg
Telephone: 02452 / 99 33 11
Email: datenschutz@kunstauktionen-duesseldorf.de
General information
In addition to the data you actively provide to us on this site (e.g. via our contact form), we collect certain technical data. This so-called metadata is automatically transmitted from your computer to our servers as soon as you visit our website (including browser, operating system or timestamp). We use this data to ensure our website is displayed correctly. In addition, we may collect data via integrated third-party providers (e.g. for external media such as map services or analytics tools). We will explain the specific purposes and legal bases in the course of this privacy policy.
Retention period
Unless a specific retention period is stated within this privacy policy, we will retain your personal data for as long as the purpose of the data processing remains valid. If you contact us with a legitimate request for erasure, or if you withdraw your consent, we will delete your data. Statutory retention obligations remain unaffected.
Legal basis for data processing
If you have consented to data processing, the processing of your personal data is based on Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, if special categories of data are processed in accordance with Article 9(1) of the GDPR. Where you have given your express consent to the transfer of personal data to third countries, the data is also processed in accordance with Article 49(1)(a) of the GDPR. If you have consented to the storage of cookies or access to information on your device (e.g. through device fingerprinting), data processing also takes place on the basis of Section 25(1) of the TDDDG. Your consent may be withdrawn at any time. If your data is necessary for the performance of a contract or for the implementation of pre-contractual measures, we process your data in accordance with Article 6(1)(b) of the GDPR. Furthermore, we process your data where this is necessary to comply with a legal obligation, on the basis of Article 6(1)(c) of the GDPR. Data processing may also take place on the basis of our legitimate interest pursuant to Article 6(1)(f) of the GDPR. The following sections of this privacy policy provide information on the respective legal bases in individual cases.
Note on data transfers to third countries and US companies without DPF certification
Please note that we use tools from companies based in third countries with inadequate data protection standards or in the USA, which are not covered by the EU-US Data Protection Framework (DPF). When using these tools, your personal data may be transferred to and processed in these countries. Please note that in these third countries with inadequate data protection standards, a level of data protection comparable to that of the EU cannot be guaranteed.
The transfer of data to the US is permitted if the recipient holds DPF certification or provides appropriate additional safeguards. Information on data transfers to third countries, including data recipients, can be found in our privacy policy.
Automated decision-making
Your personal data is not processed for the purposes of automated decision-making.
Your rights
As a data subject under the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access: You have the right to request confirmation from us as to whether your personal data is being processed and, if so, to receive further information about the processing and copies of the data being processed (Art. 15 GDPR).
- Right to rectification: You have the right to request the immediate rectification of inaccurate personal data concerning you and, where applicable, the completion of incomplete personal data (Art. 16 GDPR).
- Right to erasure: You have the right to request the immediate erasure of personal data concerning you if the legal requirements are met, in particular if the data is no longer necessary for the purposes for which it was collected and the processing is unlawful (Art. 17 GDPR).
- Right to restriction of processing: You have the right to request that we restrict the processing of your personal data where the legal conditions are met, in particular where you contest the accuracy of the data, the processing is unlawful and you oppose erasure (Art. 18 GDPR).
- Right to data portability: You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format, and you have the right to transmit this data to another controller without hindrance from us, provided this is technically feasible (Art. 20 GDPR).
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you, where the processing is based on Article 6(1)(e) or (f) of the GDPR (Article 21 of the GDPR).
- Right to withdraw consent: You have the right to withdraw your consent to the processing of personal data at any time with effect for the future. Withdrawal of your consent does not affect the lawfulness of processing carried out on the basis of your consent prior to withdrawal (Art. 7(3) GDPR).
- Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR (Article 77 of the GDPR).
Further data processing operations
General information obligations
This information is intended for customers, prospective customers, suppliers and employees. We process your personal data for the following purposes:
- To fulfil our contractual obligations to you (Art. 6(1)(b) GDPR).
- To carry out pre-contractual obligations (Art. 6(1)(b) GDPR).
- To respond to enquiries (Art. 6(1)(b) GDPR).
- Where you have given us your consent to process your personal data for specific purposes (such as to receive our newsletter), data processing takes place on the basis of your consent (Art. 6(1)(a) GDPR).
- To comply with legal obligations to which our company is subject (Art. 6(1)(c) GDPR).
- Where necessary, we also process your data to safeguard our legitimate interests, in particular to assert legal claims and defend ourselves in legal disputes, or to ensure IT security; to consult with and exchange data with credit reference agencies to assess creditworthiness and default risks; for direct marketing and market research, provided you have not objected to the use of your data for this purpose; in connection with measures for business management and the further development of services and products, in connection with measures for product and sales optimisation, in connection with risk management measures, and for the prevention or investigation of criminal offences (Art. 6(1)(f) GDPR).
Categories of recipients of personal data
Within our company, only those employees who absolutely need the data to perform their duties have access to it (need-to-know principle). Individual processes and services are carried out by carefully selected service providers, commissioned in accordance with data protection regulations, who are based within the EEA. Where service providers commissioned by us gain access to personal data whilst performing their services, data processing agreements have been concluded with them in accordance with Article 28(3) of the GDPR.
Duration of data storage
The data we process is stored for the duration of the contractual relationship and its fulfilment, and in compliance with statutory retention periods. These include, in particular, commercial and tax law retention obligations under the German Commercial Code (HGB) and the German Fiscal Code (AO). The standard retention and documentation periods amount to up to ten years. If no contractual relationship is established, we process the data only for as long as the specific purpose requires.
Data processing under the Money Laundering Prevention Act
Under Section 2(1) of the Money Laundering Prevention Act (GwG), we are obliged to comply with measures to prevent money laundering and terrorist financing. The measures prescribed by law include, amongst other things, the identification of contractual partners (Section 11 GwG) where a certain transaction threshold is exceeded. Under certain circumstances, we are also obliged to report suspicious transactions or intended transactions (Sections 27 et seq. GwG). As part of the prescribed identification and/or reporting, we collect personal data and, where necessary, pass it on to the Financial Intelligence Unit (FIU). The legal basis for the collection and transfer of data is Article 6(1)(c) of the GDPR in conjunction with the relevant statutory provisions of the GwG. Unless other statutory provisions regarding recording and retention obligations provide for a longer period in individual cases, we are obliged to retain the data for five years. Once the retention period has expired, the data will be destroyed in accordance with data protection regulations without the need for a separate request to do so.
Cookies
Cookies are small text files stored by your browser on your device to save certain information whilst you are using the website. Cookies enable us to improve various aspects of our website and make your visit more convenient.
There are various types of cookies, each serving different purposes. Temporary cookies, also known as session cookies, are stored only for the duration of your use of the website and are automatically deleted when you close your browser. Persistent cookies, on the other hand, remain stored on your device for a longer period and enable us to recognise you and your preferences on subsequent visits to the website.
Cookies can also be divided into first-party cookies and third-party cookies. First-party cookies are set by our website, whilst third-party cookies are set by other websites or service providers whose content is integrated into our website, such as plugins or analytics tools.
Cookies are used for various purposes, such as ensuring the website functions properly, storing user settings, compiling anonymous statistics on user behaviour, or displaying personalised content and advertising. The legal basis for the use of cookies varies depending on the purpose of the cookies. In some cases, the setting of cookies is based on your legitimate interest pursuant to Article 6(1)(f) of the GDPR, in order to make our website functional and user-friendly. As the website operator, we have a legitimate interest in storing necessary cookies to ensure the technically flawless and optimised provision of our services. Where we seek your consent for the use of cookies, processing is carried out on the basis of Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. Your consent may be withdrawn at any time.
Cookies are used for various purposes, such as ensuring the website functions properly, storing user settings, compiling anonymous statistics on user behaviour, or displaying personalised content and advertising. The legal basis for the use of cookies varies depending on the purpose of the cookies. In some cases, the setting of cookies is based on your legitimate interest pursuant to Article 6(1)(f) of the GDPR, in order to make our website functional and user-friendly. As the website operator, we have a legitimate interest in storing necessary cookies to ensure the technically flawless and optimised provision of our services. Where we seek your consent for the use of cookies, processing is carried out on the basis of Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. Your consent may be withdrawn at any time.
Consent with etracker
Type and Scope of Processing
We use the service "etracker" provided by etracker GmbH, Erste Brunnenstraße 1, 20459 Hamburg, Germany, on our website for obtaining, managing, and documenting consent for the use of cookies and similar technologies, as well as for privacy-friendly web analysis.
Cookies or similar technologies are used to recognise users and store their consent decisions (granted/withdrawn), timestamps, device and browser information, and the IP address in a truncated form.
Purpose and Legal Basis
The use of the service is based on the legally required consent to use cookies in accordance with Art. 6(1)(c) GDPR and s. 25(2)(2) TDDDG / applicable national law.
Retention Period
The specific retention period of the processed data is not within our control but is determined by etracker GmbH. Further information can be found in the privacy policy for etracker at: https://www.etracker.com/datenschutzerklaerung/
Data processing in detail
Below, we provide information on the individual processing operations, the scope and purpose of data processing, the legal basis, the obligation to provide your data and the respective storage period. No automated decision-making, including profiling, takes place in individual cases.
Provision of the website
When you access and use our website, we collect the personal data that your browser automatically transmits to our server. The following information is temporarily stored in a so-called log file:
- IP address of the requesting computer
- Date and time of access
- Name and URL of the file accessed
- Website from which the access is made (referrer URL)
- Browser used and, where applicable, your computer’s operating system, as well as the name of your internet service provider
Our website is not hosted by us, but by a service provider who processes the aforementioned data on our behalf for the purpose of providing the website, in accordance with Article 28 of the GDPR.
The use of the hosting provider is for the purpose of fulfilling our contractual obligations towards our potential and existing customers (Article 6(1)(b) GDPR) and in the interest of a secure, fast and efficient provision of our online services by a professional provider (Article 6(1)(f) GDPR).
We use the following hosting provider:
ALL-INKL.COM - Neue Medien Münnich
Owner: René Münnich
Hauptstraße 68 | D-02742 Friedersdorf
Contact form
Nature and scope of processing
When you send us enquiries (e.g. via the contact form, email or telephone), we store all data resulting from this (e.g. name, email address, subject of the enquiry, etc.). We require this data to process your enquiry and to be able to answer any follow-up questions . We will not pass on this data without your consent.
Purpose and legal basis
The processing of this data is based on Article 6(1)(b) of the GDPR, provided that your enquiry relates to the performance of a contract or is necessary for the implementation of pre-contractual measures. Otherwise, the processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Article 6(1)(f) of the GDPR) or on your consent (Article 6(1)(a) of the GDPR) if you have previously given it.
Retention period
The data you enter in the contact form will remain with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. once your enquiry has been processed). Mandatory legal provisions – in particular retention periods – remain unaffected.
Contact form for applicants
Nature and scope of processing
We collect and process the personal data of applicants. Such data processing may also take place electronically, for example, when applicants submit application documents to us by email or via a web form on our website. On our website, we offer you the option of submitting applications for advertised vacancies to us by email.
Purpose and legal basis
We process applicants’ personal data in accordance with legal requirements for the purpose of establishing an employment relationship (Art. 6(1)(b) GDPR). You are not obliged to provide us with this data. However, without this data, we cannot carry out an application process with you.
If your application is successful, the data you have submitted will be stored in our data processing systems on the basis of Article 6(1)(b) of the GDPR and, insofar as you provide us with special categories of personal data such as health information, on the basis of Article 9(2)(b) for the purpose of carrying out the employment relationship.
We also use the professional networking services LinkedIn and XING to approach potential candidates. In this regard, the operators of these networks act on our behalf as data processors in accordance with our instructions. The legal basis for the processing of data when approaching potential candidates on our behalf is Article 6(1)(f) of the GDPR (our legitimate interests). If, as a result of such an approach, you send us your application, we will process your data for the purpose of establishing an employment relationship as described above, on the basis of Article 6(1)(b) of the GDPR.
Retention period
In the event of a rejection, your data will be stored for a period of 6 months beyond the conclusion of the application process. This is done to safeguard our legitimate interests, in order to assess whether we require the data to defend against any claims arising in connection with the application process. We are then obliged to delete or anonymise your data. In this case, the data will only be available to us as so-called metadata without any direct personal reference for statistical analysis (for example, the proportion of female and male applicants, the number of applications per period, etc.).
If it becomes apparent that further storage of the data is necessary after the expiry of the 6-month period to safeguard our legitimate interests (e.g. due to an impending or pending legal dispute), deletion will only take place once the purpose for continued storage no longer applies. The legal basis for this further data storage is our legitimate interests in the assertion, exercise or defence of civil law claims (Art. 6(1)(f) GDPR in conjunction with Section 24(1)(2) BDSG or, where special categories of personal data are stored, Art. 9(2)(f) GDPR in conjunction with Section 24(2) BDSG).
Inclusion in the applicant pool
As part of the application process, we offer applicants the opportunity to be included in our “talent pool” for a period of 24 months on the basis of consent within the meaning of Article 6(1)(a) and Article 9(2)(a) of the GDPR. If you have provided special categories of personal data in your application, such as health information, your consent also extends to this data. You are not obliged to provide us with your application data for our talent pool. However, without this data, we cannot consider you for future vacancies unless you submit a new application.
Consent to the inclusion of application data in the Talent Pool is voluntary and may be withdrawn at any time with future effect. Withdrawal of consent does not affect the lawfulness of data processing carried out on the basis of consent prior to withdrawal.
Your application documents will be deleted from the talent pool at the latest upon expiry of the retention period, or in the event of a withdrawal of consent, or upon acceptance of a job offer from one of the companies responsible for the talent pool.
If, as part of the application process, you receive an offer of employment from us and accept it, we or that company will store the personal data collected during the application process for the purpose of managing the employment relationship. The legal basis for this data processing is Article 6(1)(b) of the GDPR or, insofar as you provide us with special categories of personal data such as health information, Article 9(2)(b).
Newsletter
We offer our newsletter on this website. If you wish to subscribe to it, we require your email address and further data to verify that the email address belongs to you and that you consent to receiving the newsletter. No other personal data is collected unless you provide it voluntarily (e.g. name, telephone number, place of residence, etc.).
When processing the data you provide when signing up for the newsletter, we rely exclusively on your consent under Article 6(1)(a) of the GDPR as the legal basis. You may withdraw your consent to the processing and storage of your personal data at any time (e.g. via the ‘Unsubscribe’ link in the newsletter) with effect for the future.
We store the personal data you have provided for the purpose of receiving the newsletter until you unsubscribe from the newsletter via us or the mailing service provider. This does not apply to data we have stored about you for other purposes.
If you unsubscribe from the newsletter mailing list, your email address will be stored by us or the mailing service provider on a blacklist for an indefinite period. This is done to prevent future mailings from being sent to you. The data from the blacklist is used exclusively for this purpose and is not combined with other data. This is not only in your interest, but also in our legitimate interest under Article 6(1)(f) of the GDPR to fulfil our legal obligations regarding the sending of newsletters. You may object to the storage of your data if your personal interests override our legitimate interest.
Brevo
This website uses Brevo to send newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.
Brevo is a service for organising and analysing newsletter distribution. The data you provide to subscribe to the newsletter is stored on Brevo’s servers in Germany.
Brevo enables us to analyse our newsletter campaigns. For example, we can see whether a newsletter message has been opened and which links have been clicked. This allows us to determine which links have been clicked most frequently.
Brevo also allows us to group newsletter recipients into different categories (‘clustering’). For example, newsletter recipients can be grouped by age, gender or place of residence. This enables us to tailor the newsletters more effectively to the respective target groups.
If you do not wish to be analysed by Brevo, you must unsubscribe from the newsletter. We provide a link for this purpose in every newsletter message.
Further information on Brevo’s features can be found here: https://www.brevo.com/de/newsletter-software/.
Data processing is carried out on the basis of your consent (Art. 6(1)(a) GDPR). You may withdraw this consent at any time. The lawfulness of data processing operations that have already taken place remains unaffected by the withdrawal.
The data stored by us for the purpose of receiving the newsletter will be retained by us or the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the distribution list once you have unsubscribed. Data stored by us for other reasons remains unaffected by this.
After you unsubscribe from the newsletter list, your email address may be stored by us or the newsletter service provider in a block list to prevent future mailings. The data from the block list is used solely for this purpose and is not merged with other data. This serves both your and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Article 6(1)(f) of the GDPR). Storage on the block list is not time-limited. You may object to this storage provided that your interests override our legitimate interest.
Further information on data protection at Brevo can be found here: https://www.brevo.com/de/legal/privacypolicy/.
To ensure that personal data is processed in accordance with our guidelines and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Registration of a customer account
Nature and scope of processing
As part of the order processing, we collect your personal data for the registration of a customer account. You can choose whether you wish to order as a guest or register a permanent user account. The information collected via the mandatory fields during registration is identical in both cases and is required for processing the order in the online shop. When registering a permanent user account, we also collect a password chosen by you. In addition, you may voluntarily provide further information which you consider necessary for the processing of the order.
Your personal data will only be disclosed to third parties (e.g. delivery service providers / freight forwarders) and processors in accordance with Article 28 of the GDPR to the extent necessary for the processing of your order.
Purpose and legal basis
We process your personal data for the purpose of registering a customer account to fulfil a contract with you in accordance with Article 6(1)(b) of the GDPR. There is a contractual obligation to provide your data insofar as it relates to the mandatory fields, as this information is necessary for the identification of your person and for the fulfilment of the contract on our part. There is no legal obligation to provide the data . Without the provision of this information, it is not possible to place an order in our online shop and thus conclude a contract. There is no obligation to provide the additional information provided voluntarily. It is possible to place an order in our online shop even without disclosing the voluntary information.
The additional processing of your password for the registration of a permanent user account is carried out for the purpose of providing a customer account and displaying your previous purchases, as well as for storing your purchase-related data (e.g. storage of billing address, various delivery addresses) on the basis of your consent in accordance with Article 6(1)(a) of the GDPR. By deleting your customer account, you may at any time withdraw your consent with future effect in accordance with Article 7(3) of the GDPR.
Retention period
If you place an order as a guest, your personal data will be stored until your order has been fully processed (end of the contract). If you register a permanent customer account, we will store purchase-related data beyond the end of the contract until you withdraw your consent (deletion of the customer account). In both cases, your data will only be stored further if statutory retention obligations (e.g. under tax and commercial law) apply.
Presence on social media platforms
We maintain public profiles on various social networks via our website. You can find more detailed information about the social networks we use in the relevant sections of our privacy policy.
Social networks such as Facebook, Twitter and others can comprehensively analyse your user behaviour when you visit their websites or a website with integrated social media content (e.g. ‘Like’ buttons or advertising banners). Visiting our social media pages triggers numerous data processing operations relevant to data protection:
If you are logged into your social media account and visit our social media presence, the operator of the social media portal may associate this visit with your user account. However, your personal data may also be collected even if you are not logged in or do not have an account with the relevant social media portal. In this case, data collection takes place, for example, via cookies stored on your device or by recording your IP address.
Using the data collected in this way, the operators of the social media platforms can create user profiles containing your preferences and interests. This allows interest-based advertising to be displayed to you both on and off the respective social media platform. If you have an account with the relevant social network, interest-based advertising may be displayed on all devices on which you are logged in or have been logged in.
Please note that we cannot track all processing activities on social media platforms. Depending on the provider, further processing operations may therefore be carried out by the operators of the social media platforms. For details, please refer to the terms of use and privacy policies of the respective social media platforms.
Legal basis for data processing
Our social media presence serves to ensure the most comprehensive online presence possible. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the GDPR. The analysis processes initiated by the social networks may be based on different legal grounds, which must be specified by the operators of the social networks (e.g. consent within the meaning of Article 6(1)(a) of the GDPR).
Data controller and exercising of rights
When you visit our social media pages (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered by that visit. You may, in principle, exercise your rights (right of access, rectification, erasure, restriction of processing, data portability and the right to lodge a complaint) both against us and against the operator of the relevant social media portal (e.g. against Facebook).
Despite our joint responsibility with the social media portal operators, we do not have full control over the data processing operations of the social media portals. Our options depend largely on the corporate policy of the respective provider.
Duration of data storage
Data collected directly by us via our social media presence will be deleted from our systems as soon as you request us to delete it, withdraw your consent to its storage, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory legal provisions – in particular retention periods – remain unaffected.
We have no influence over the duration of storage of your data that is stored by the operators of the social networks for their own purposes. For further details, please contact the operators of the social networks directly (e.g. via their privacy policy, see below).
Facebook page
Our company has a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter ‘Meta’). According to Meta, the data collected is also transferred to the USA and other third countries.
We have entered into a joint processing agreement (Controller Addendum) with Meta. This agreement sets out which data processing operations we and Meta are responsible for when you visit our Facebook page. You can view the agreement via the following link: https://www.facebook.com/legal/terms/page_controller_addendum.
You can adjust your advertising settings yourself in your user account. To do so, click on the following link and log in: https://www.facebook.com/settings?tab=ads.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards.
Data transfers to the US are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.
For further information, please refer to Facebook’s privacy policy: https://www.facebook.com/about/privacy/.
Instagram page
Our company has a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards.
Data transfers to the US are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://help.instagram.com/519522125107875 and https://de-de.facebook.com/help/566994660333381.
For further information on how your personal data is handled, please refer to Instagram’s privacy policy: https://help.instagram.com/519522125107875.
Twitter page
Our company uses the short message service X (formerly Twitter). The provider is Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland.
You can adjust your X privacy settings yourself in your user account; to do so, log in via the following link: https://x.com/settings/account/personalization.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards.
Data transfers to the US are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://gdpr.x.com/en/controller-to-controller-transfers.html.
For further information, please refer to X’s privacy policy: https://x.com/de/privacy.
Communication via WhatsApp
For communication with our customers and other third parties, we use, among other things, the instant messaging service WhatsApp Business, provided by WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
When you communicate with us via WhatsApp, the chats are end-to-end encrypted. This is designed to prevent WhatsApp or third parties from accessing the content of the chat. However, WhatsApp does have access to metadata generated during the communication process (e.g. sender, recipient and time). WhatsApp shares the personal data it collects with its parent company, Meta, which is based in the USA. Further details on data processing can be found in WhatsApp’s Privacy Policy at: https://www.whatsapp.com/legal/#privacy-policy.
The use of WhatsApp is based on our legitimate interest in communicating as quickly and effectively as possible with customers, prospective customers and other business and contractual partners (Art. 6(1)(f) GDPR). If you have previously given your consent to data processing, the processing of your data takes place solely on the basis of Article 6(1)(a) of the GDPR; consent may be withdrawn at any time.
The content of communications exchanged between us and on WhatsApp remains with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. once your enquiry has been processed). Mandatory legal provisions – in particular retention periods – remain unaffected.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards.
We have configured our WhatsApp accounts so that there is no automatic data synchronisation with the address book on the smartphones in use.
To ensure that personal data is processed in accordance with our guidelines and in compliance with the GDPR, we have entered into a Data Processing Agreement (DPA) with the provider.
Services and tools used
Google Fonts
Nature and scope of data processing
This website uses web fonts provided by Google to ensure consistent font display. When you visit the site, your browser loads the required web fonts into your browser cache so that text and fonts are displayed correctly. To do this, the browser you are using establishes a connection to Google’s servers. As a result, Google becomes aware of your IP address.
Legal basis
The use of Google Web Fonts is based on our legitimate interest in the consistent display of the typography on our website (Art. 6(1)(f) GDPR). If consent has been requested (e.g. consent to the storage of cookies), the processing of data takes place exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. This consent may be withdrawn at any time. If your browser does not support web fonts, a standard font from your computer will be used. Further information on Google Web Fonts can be found here: https://developers.google.com/fonts/faq. Google’s privacy policy can be found here: https://policies.google.com/privacy?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
Data controller and exercising of rights
When you visit our social media pages (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered by that visit. You may, in principle, exercise your rights (right of access, rectification, erasure, restriction of processing, data portability and the right to lodge a complaint) both against us and against the operator of the relevant social media portal (e.g. against Facebook).
Despite our joint responsibility with the social media portal operators, we do not have full control over the data processing operations of the social media portals. Our options depend largely on the corporate policy of the respective provider.
Duration of data storage
Data collected directly by us via our social media presence will be deleted from our systems as soon as you request us to delete it, withdraw your consent to its storage, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory legal provisions – in particular retention periods – remain unaffected.
We have no influence over the duration of storage of your data that is stored by the operators of the social networks for their own purposes. For further details, please contact the operators of the social networks directly (e.g. via their privacy policy, see below).
Facebook page
Our company has a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter ‘Meta’). According to Meta, the data collected is also transferred to the USA and other third countries.
We have entered into a joint processing agreement (Controller Addendum) with Meta. This agreement sets out which data processing operations we and Meta are responsible for when you visit our Facebook page. You can view the agreement via the following link: https://www.facebook.com/legal/terms/page_controller_addendum.
You can adjust your advertising settings yourself in your user account. To do so, click on the following link and log in: https://www.facebook.com/settings?tab=ads.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards.
Data transfers to the US are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.
For further information, please refer to Facebook’s privacy policy: https://www.facebook.com/about/privacy/.
Instagram page
Our company has a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards.
Data transfers to the US are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://help.instagram.com/519522125107875 and https://de-de.facebook.com/help/566994660333381.
For further information on how your personal data is handled, please refer to Instagram’s privacy policy: https://help.instagram.com/519522125107875.
Twitter page
Our company uses the short message service X (formerly Twitter). The provider is Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland.
You can adjust your X privacy settings yourself in your user account; to do so, log in via the following link: https://x.com/settings/account/personalization.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards.
Data transfers to the US are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://gdpr.x.com/en/controller-to-controller-transfers.html.
For further information, please refer to X’s privacy policy: https://x.com/de/privacy.
Communication via WhatsApp
For communication with our customers and other third parties, we use, among other things, the instant messaging service WhatsApp Business, provided by WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
When you communicate with us via WhatsApp, the chats are end-to-end encrypted. This is designed to prevent WhatsApp or third parties from accessing the content of the chat. However, WhatsApp does have access to metadata generated during the communication process (e.g. sender, recipient and time). WhatsApp shares the personal data it collects with its parent company, Meta, which is based in the USA. Further details on data processing can be found in WhatsApp’s Privacy Policy at: https://www.whatsapp.com/legal/#privacy-policy.
The use of WhatsApp is based on our legitimate interest in communicating as quickly and effectively as possible with customers, prospective customers and other business and contractual partners (Art. 6(1)(f) GDPR). If you have previously given your consent to data processing, the processing of your data takes place solely on the basis of Article 6(1)(a) of the GDPR; consent may be withdrawn at any time.
The content of communications exchanged between us and on WhatsApp remains with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. once your enquiry has been processed). Mandatory legal provisions – in particular retention periods – remain unaffected.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards.
We have configured our WhatsApp accounts so that there is no automatic data synchronisation with the address book on the smartphones in use.
To ensure that personal data is processed in accordance with our guidelines and in compliance with the GDPR, we have entered into a Data Processing Agreement (DPA) with the provider.
Services and tools used
Google Fonts
Nature and scope of data processing
This website uses web fonts provided by Google to ensure consistent font display. When you visit the site, your browser loads the required web fonts into your browser cache so that text and fonts are displayed correctly. To do this, the browser you are using establishes a connection to Google’s servers. As a result, Google becomes aware of your IP address.
Legal basis
The use of Google Web Fonts is based on our legitimate interest in the consistent display of the typography on our website (Art. 6(1)(f) GDPR). If consent has been requested (e.g. consent to the storage of cookies), the processing of data takes place exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. This consent may be withdrawn at any time. If your browser does not support web fonts, a standard font from your computer will be used. Further information on Google Web Fonts can be found here: https://developers.google.com/fonts/faq. Google’s privacy policy can be found here: https://policies.google.com/privacy?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active.
Google Maps
Nature and scope of data processing
This website uses Google Maps. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. To use the functions, it is necessary to store your IP address. As a rule, the information is transmitted to a Google server and stored there. The provider of this website has no influence over this data transmission. If Google Maps is activated, Google may use web fonts to ensure a consistent display of fonts. When you access Google Maps, your browser loads the required fonts into your browser cache so that the fonts are displayed correctly.
Legal basis
The use of Google Maps is based on our legitimate interest in presenting our online services in an appealing manner and in ensuring that the locations we specify are easy to find (Art. 6(1)(f) GDPR). If consent has been requested, the processing of data takes place exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. This consent may be withdrawn at any time. Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses: https://business.safety.google/gdprcontrollerterms/sccs/ and https://business.safety.google/gdprcontrollerterms/.
Google’s privacy policy can be found here: https://policies.google.com/privacy?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active.
etracker
On this website, we use services and functions provided by etracker, offered by etracker GmbH, Erste Brunnenstraße 1, 20459 Hamburg, Germany, to analyse the user behaviour of our website visitors.
Through this analysis, visitor data is collected which can be used to create pseudonymised user profiles. In doing so, etracker uses technologies (e.g. cookies or fingerprinting systems) to recognise visitors when they return to the website. The data collected is not used to identify you as a user or to combine it with other personal information about you, unless you give your consent to do so.
When using etracker, we rely on Article 6(1)(f) of the GDPR as the legal basis for the processing of personal data, as we have a legitimate interest in analysing the use of our website. This enables us to optimise our online presence and services for you. If you have previously given your consent to data processing on this website by etracker, the processing of your data takes place solely on the legal basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time.
Data processing
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Clarity
Nature and scope of processing
We have integrated Clarity into our website. Clarity is a service provided by Microsoft Corporation and offers optimisation tools that analyse the behaviour and feedback of users of our website using analytics and feedback tools.
Clarity uses cookies and other browser technologies to evaluate user behaviour and recognise users.
This information is used, among other things, to compile reports on website activity and to statistically analyse visitor data. Furthermore, Clarity records clicks, mouse movements and scroll depths to create so-called heatmaps and session replays.
In this case, your data is transferred to the operator of Clarity, Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, United States.
Purpose and legal basis
The use of Clarity is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. Data transfers to the USA are carried out in accordance with Article 45(1) of the GDPR on the basis of the European Commission’s adequacy decision. The US companies involved and/or their US sub-processors are certified under the EU-US Data Privacy Framework (EU-US DPF).
In cases where no adequacy decision has been adopted by the European Commission (including US companies that are not certified under the EU-US DPF), we have agreed on other appropriate safeguards with the recipients of the data in accordance with Articles 44 et seq. of the GDPR. Unless otherwise stated, these are the EU Commission’s standard contractual clauses in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE.
In addition, prior to such a transfer to a third country, we will obtain your consent in accordance with Article 49(1)(a) of the GDPR, which you provide via the Consent Manager (or other forms, registrations, etc.). We would like to draw your attention to the fact that transfers to third countries may involve risks of which the details are unknown (e.g. data processing by the security authorities of the third country, the exact scope of which and the consequences for you we do not know, over which we have no influence and of which you may not become aware).
Retention period
We have no influence over the specific retention period of the processed data; this is determined by Microsoft Corporation. Further information can be found in the privacy policy for Clarity: https://privacy.microsoft.com/en-us/privacystatement.Rechtsgrundlagen
When using Clarity, we rely on Article 6(1)(f) of the GDPR as the legal basis for the storage and analysis of personal data, as we have a legitimate interest in analysing the use of our website. This enables us to optimise our online presence and services for you. If you have previously given your consent to data processing by Clarity on this website, the processing of your data takes place solely on the legal basis of Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TTDSG. You may withdraw your consent at any time.
The transfer of your personal data to the USA is based on the EU Commission’s Standard Contractual Clauses. Further information on this can be found at https://docs.microsoft.com/en-us/clarity/faq.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000KzNaAAK&status=Active
Data processing
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
AddToAny
Nature and scope of processing
We have integrated AddToAny into our website. AddToAny is a service provided by AddToAny. We use AddToAny by placing share buttons on our website, enabling website visitors to share content on social networks and apps such as Facebook, Twitter, Pinterest, LinkedIn, Google+, WhatsApp and other services.
When you access this content, you establish a connection to AddToAny’s servers, whereby your IP address is transmitted in an anonymised form. According to AddToAny, no personal data is processed.
Purpose and legal basis
The use of AddToAny is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
Retention period
We have no influence over the specific storage period of the processed data; this is determined by AddToAny. Further information can be found in the AddToAny privacy policy: https://www.addtoany.com/privacy.
Vimeo
Our company has a profile on Vimeo. The provider is Vimeo, Inc., 555 West 18th Street, New York 10011, USA.
Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses and, according to Vimeo, on ‘legitimate business interests’. Further details can be found here: https://vimeo.com/privacy.
For further information on the handling of your personal data, please refer to Vimeo’s privacy policy: https://vimeo.com/privacy.
Vimeo Video
This website uses plugins from the video portal Vimeo. The provider is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA. When you play a Vimeo video on this website, a connection is established with their servers. The Vimeo server is informed which of our pages you have visited. Vimeo also obtains your IP address. However, we have configured the settings so that Vimeo cannot track your user activity and will not set any cookies.
Legal basis
The use of Vimeo is based on our legitimate interest in presenting our online services in an appealing manner (Art. 6(1)(f) GDPR). If consent has been requested, the processing of data is carried out exclusively on the basis of your consent in accordance with Art. 6(1)(a) GDPR and Section 25(1) TDDDG. This consent may be withdrawn at any time. The transfer of data to the USA is based on the EU Commission’s Standard Contractual Clauses. Vimeo’s privacy policy can be found here: https://vimeo.com/privacy.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards.
Google reCAPTCHA
This website uses Google reCAPTCHA. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Nature and scope of data processing
reCAPTCHA is used to verify data entry (e.g. in a contact form) on this website. Specifically, it checks whether the entry is made by a human or by an automated programme. Google reCAPTCHA analyses the behaviour of the website visitor based on various characteristics. The analysis begins automatically as soon as the visitor accesses the website. The data collected during the analysis, such as the IP address, the duration of the website visitor’s stay or the mouse movements made, is forwarded to Google.
Website visitors are not notified that an analysis is taking place; these processes run entirely in the background.
Legal basis
The storage and analysis of data is based on our legitimate interest in protecting our web services from malicious automated spying and spam (Art. 6(1)(f) GDPR). If consent has been requested, the processing of data takes place exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. This consent may be withdrawn at any time.
Google’s privacy policy and terms of service can be found at the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
PRIVACY POLICY
We are delighted that you are visiting our website. The protection and security of your personal information when using our website is very important to us. We would therefore like to take this opportunity to inform you about which of your personal data we collect when you visit our website and for what purposes it is used.
Personal data refers to individual details about the personal or factual circumstances of an identified or identifiable natural person (data subject), e.g. name, address, email addresses, user behaviour. This is therefore data that we can use to identify you. In addition, you will also find occasional information here about data processing procedures outside this website (e.g. video conferences or newsletters).
Responsible for data processing
Responsible
For the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR)
Hargesheimer Kunstauktionen Düsseldorf GmbH
Friedrich-Ebert-Strasse 11+12
40210 Düsseldorf
Telephone: +49 (0) 211 – 30 200 10
Email: info@kunstauktionen-duesseldorf.de
Data Protection Officer
exkulpa gmbh
Waldfeuchterstr. 266
52525 Heinsberg
Telephone: 02452 / 99 33 11
Email: datenschutz@kunstauktionen-duesseldorf.de
General information
In addition to the data that you actively provide to us on this page (e.g. via our contact form), we collect some technical data. This so-called metadata is automatically transmitted from your computer to our servers as soon as you enter our website (including browser, operating system or timestamp). We use this data to ensure that our website is displayed correctly. In addition, we may collect data via integrated third-party providers (e.g. for external media such as map services or analysis tools). We will explain the individual purposes and legal bases in the course of this privacy policy.
Storage period
Unless a separate storage period is specified in this privacy policy, we will store your personal data for as long as the purpose of data processing exists. If you contact us with a legitimate request for deletion or revoke your consent, we will delete your data. Statutory retention obligations remain unaffected.
Legal basis for data processing
If you have consented to data processing, your personal data will be processed on the basis of Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR if special categories of data are processed in accordance with Art. 9 (1) GDPR. If you have expressly consented to the transfer of personal data to third countries, the data will also be processed in accordance with Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or access to information on your end device (e.g. through device fingerprinting), data processing will also take place on the basis of Section 25(1) TDDDG. Your consent can be revoked at any time. If your data is necessary for the performance of a contract or for the implementation of pre-contractual measures, we process your data in accordance with Art. 6 (1) lit. b GDPR. In addition, we process your data if this is necessary to fulfil a legal obligation, on the basis of Art. 6 (1) lit. c GDPR. Data processing may also take place on the basis of our legitimate interest in accordance with Art. 6 (1) lit. f GDPR. In the following sections of this privacy policy, you will be informed about the respective legal basis in individual cases.
Note on data transfer to third countries and US companies without DPF certification
Please note that we use tools from companies based in third countries or the USA that are not covered by the EU-US Privacy Shield Framework (DPF) and where data protection is not guaranteed. When using these tools, your personal data may be transferred to these countries and processed there. Please note that in these third countries, a level of data protection comparable to that in the EU cannot be guaranteed.
We would like to clarify that the USA generally offers a level of data protection comparable to that of the EU. The transfer of data to the USA is permitted if the recipient has DPF certification or provides appropriate additional safeguards. Information about data transfers to third countries, including data recipients, can be found in our privacy policy.
Automated decision-making
Your personal data will not be processed for the purpose of automated decision-making.
Your rights
As a data subject under the General Data Protection Regulation (GDPR), you have the following rights:
• Right of access: You have the right to request confirmation from us as to whether your personal data is being processed and, if so, to receive further information about the processing and copies of the data being processed (Art. 15 GDPR).
• Right to rectification: You have the right to request the immediate rectification of inaccurate personal data concerning you and, where applicable, the completion of incomplete personal data (Art. 16 GDPR).
• Right to erasure: You have the right to request the immediate erasure of personal data concerning you if the legal requirements are met, in particular if the data is no longer necessary for the purposes pursued and the processing is unlawful (Art. 17 GDPR).
• Right to restriction of processing: You have the right to request that we restrict the processing of your personal data if the legal requirements are met, in particular if you dispute the accuracy of the data, the processing is unlawful and you refuse to have it erased (Art. 18 GDPR).
• Right to data portability: You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format, and you have the right to transmit this data to another controller without hindrance from us, provided that this is technically feasible (Art. 20 GDPR).
• Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you, if the processing is based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR).
• Right to withdraw consent: You have the right to withdraw your consent to the processing of personal data at any time with effect for the future. The withdrawal of your consent does not affect the lawfulness of the processing carried out on the basis of your consent until withdrawal (Art. 7(3) GDPR).
• Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR (Art. 77 GDPR).
Further data processing procedures
General information obligations
This information is intended for customers, interested parties, suppliers and employees. We process your personal data for the following purposes:
• To fulfil our contractual obligations to you (Art. 6(1)(b) GDPR).
• To perform pre-contractual obligations (Art. 6(1)(b) GDPR).
• To respond to enquiries (Art. 6(1)(b) GDPR).
• If you have given us your consent to process your personal data for specific purposes (e.g. to receive our newsletter), data processing is based on your consent (Art. 6(1)(a) GDPR).
• To fulfil legal obligations to which our company is subject (Art. 6(1)(c) GDPR).
• Where necessary, we also process your data to protect our legitimate interests, in particular to assert legal claims and defend ourselves in legal disputes or to ensure IT security, to consult and exchange data with credit agencies to determine creditworthiness and default risks, for direct marketing and market research, provided you have not objected to the use of your data for this purpose, for measures relating to business management and the further development of services and products, for measures relating to product and sales optimisation, for measures relating to risk management, for the prevention or investigation of criminal offences (Art. 6 para. 1 lit. f GDPR).
Categories of recipients of personal data
Within our company, only those employees who absolutely need the data to perform their tasks have access to it (need-to-know principle). Individual processes and services are carried out by carefully selected service providers based within the EEA who are commissioned in accordance with data protection regulations. If service providers commissioned by us have access to personal data when performing their services, data processing agreements have been concluded with them in accordance with Art. 28 (3) GDPR.
Duration of data storage
The data we process is stored for the duration of the existence and execution of the contractual relationship and in compliance with statutory retention periods. These are, in particular, commercial and tax law retention obligations under the German Commercial Code (HGB) and the German Fiscal Code (AO). The regular retention and documentation periods are up to ten years. If no contractual relationship is established, we only process the data for as long as the specific purpose requires.
Data processing in accordance with the Money Laundering Prevention Act
According to Section 2 (1) GwG (Money Laundering Prevention Act), we are obliged to comply with measures to prevent money laundering and terrorist financing. The measures required by law include, among other things, the identification of contractual partners (Section 11 GwG) if a certain transaction amount is exceeded.
Under certain circumstances, we are also obliged to report suspicious transactions or intended transactions (Sections 27 ff. GwG). As part of the prescribed identification and/or reporting process, we collect personal data and, if necessary, pass it on to the Financial Intelligence Unit (FIU). The legal basis for data collection and transfer is Art. 6 (1) lit. c GDPR in conjunction with the respective legal provisions of the GwG.
Unless other legal provisions on recording and retention obligations provide for a longer period in individual cases, we are obliged to retain the data for five years. Once the retention period has expired, the data will be destroyed in accordance with data protection regulations without the need for a separate request.
This privacy policy sets out how this website (hereafter "the Store") uses and protects any information that you give the Store while using this website. The Store is committed to ensuring that your privacy is protected. Should we ask you to provide certain information by which you can be identified when using this website, then you can be assured that it will only be used in accordance with this privacy statement. The Store may change this policy from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes.
What we collect
We may collect the following information:
- name
- contact information including email address
- demographic information such as postcode, preferences and interests
- other information relevant to customer surveys and/or offers
For the exhaustive list of cookies we collect see the List of cookies we collect section.
What we do with the information we gather
We require this information to understand your needs and provide you with a better service, and in particular for the following reasons:
- Internal record keeping.
- We may use the information to improve our products and services.
- We may periodically send promotional emails about new products, special offers or other information which we think you may find interesting using the email address which you have provided.
- From time to time, we may also use your information to contact you for market research purposes. We may contact you by email, phone, fax or mail. We may use the information to customise the website according to your interests.
Security
We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.
How we use cookies
A cookie is a small file which asks permission to be placed on your computer's hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.
We use traffic log cookies to identify which pages are being used. This helps us analyse data about web page traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system.
Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us. You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.
Links to other websites
Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.
Controlling your personal information
You may choose to restrict the collection or use of your personal information in the following ways:
- whenever you are asked to fill in a form on the website, look for the box that you can click to indicate that you do not want the information to be used by anybody for direct marketing purposes
- if you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by letting us know using our Contact Us information
We will not sell, distribute or lease your personal information to third parties unless we have your permission or are required by law to do so. We may use your personal information to send you promotional information about third parties which we think you may find interesting if you tell us that you wish this to happen.
You may request details of personal information which we hold about you under the Data Protection Act 1998. A small fee will be payable. If you would like a copy of the information held on you please email us this request using our Contact Us information.
If you believe that any information we are holding on you is incorrect or incomplete, please write to or email us as soon as possible, at the above address. We will promptly correct any information found to be incorrect.
List of cookies we collect
The table below lists the cookies we collect and what information they store.
| Cookie Name | Cookie Description |
|---|---|
| FORM_KEY | Stores randomly generated key used to prevent forged requests. |
| PHPSESSID | Your session ID on the server. |
| GUEST-VIEW | Allows guests to view and edit their orders. |
| PERSISTENT_SHOPPING_CART | A link to information about your cart and viewing history, if you have asked for this. |
| STF | Information on products you have emailed to friends. |
| STORE | The store view or language you have selected. |
| USER_ALLOWED_SAVE_COOKIE | Indicates whether a customer allowed to use cookies. |
| MAGE-CACHE-SESSID | Facilitates caching of content on the browser to make pages load faster. |
| MAGE-CACHE-STORAGE | Facilitates caching of content on the browser to make pages load faster. |
| MAGE-CACHE-STORAGE-SECTION-INVALIDATION | Facilitates caching of content on the browser to make pages load faster. |
| MAGE-CACHE-TIMEOUT | Facilitates caching of content on the browser to make pages load faster. |
| SECTION-DATA-IDS | Facilitates caching of content on the browser to make pages load faster. |
| PRIVATE_CONTENT_VERSION | Facilitates caching of content on the browser to make pages load faster. |
| X-MAGENTO-VARY | Facilitates caching of content on the server to make pages load faster. |
| MAGE-TRANSLATION-FILE-VERSION | Facilitates translation of content to other languages. |
| MAGE-TRANSLATION-STORAGE | Facilitates translation of content to other languages. |