Privacy policy
Privacy Policy
### 1) Information on the Collection of Personal Data and Contact Details of the Data Controller
1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data includes all data that can be used to identify you personally.
1.2 The responsible party for data processing on this website, within the meaning of the General Data Protection Regulation (GDPR), is Veridium Ventures LLC Email: info@Filternatur.com. The person responsible for processing personal data is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.
1.3 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the responsible party). You can recognize an encrypted connection by the "https://" protocol and the lock symbol in your browser's address bar.
### 2) Data Collection When Visiting Our Website
When you use our website for informational purposes only, i.e., when you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files"). When you access our website, we collect the following data that is technically necessary for us to display the website to you:
- Our visited website
- Date and time of access
- Amount of data sent in bytes
- Source/reference from which you came to the page
- Used browser
- Used operating system
- Used IP address (if applicable, in anonymized form)
Processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. Data will not be disclosed or used in any other way. However, we reserve the right to review the server log files retrospectively should concrete indications of unlawful use arise.
### 3) Hosting & Content Delivery Network
**Hosting by Shopify**
We use the Shopify system from the service provider Shopify International Limited, Victoria Buildings, 2nd floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify"), for hosting and displaying the online shop based on processing on our behalf. All data collected on our website is processed on Shopify's servers. As part of Shopify's services, data may also be transferred to Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada, Shopify Data Processing (USA) Inc., Shopify Payments (USA) Inc., or Shopify (USA) Inc. In the event of data transfer to Shopify Inc. in Canada, the appropriate level of data protection is guaranteed by an adequacy decision of the European Commission. Further information on Shopify's privacy policy can be found on the following website: [Shopify Privacy Policy](https://www.shopify.com/legal/privacy).
Further processing on servers other than those of Shopify will only take place within the scope communicated below.
### 4) Cookies
To make visiting our website attractive and to enable the use of certain functions, we use cookies, i.e., small text files stored on your device. Some of these cookies are deleted automatically after closing the browser (so-called "session cookies"), while others remain on your device longer and enable the storage of page settings (so-called "persistent cookies"). In the latter case, you can view the storage duration in the cookie settings of your web browser.
If personal data is processed through individual cookies implemented by us, processing is carried out in accordance with Art. 6 para. 1 lit. b GDPR either for contract execution, in accordance with Art. 6 para. 1 lit. a GDPR in the case of granted consent, or in accordance with Art. 6 para. 1 lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website as well as a customer-friendly and effective website visit.
You can set your browser to inform you about the setting of cookies and to decide individually whether to accept them or to exclude the acceptance of cookies for certain cases or in general. Please note that if cookies are not accepted, the functionality of our website may be limited.
### 5) Contacting Us
**5.1 LuckyOrange (LuckyOrange LLC)**
This website collects and stores anonymized data using technologies from Lucky Orange LLC, 8680 W 96th St, Overland Park, KS 66212, USA, ([www.luckyorange.com](https://www.luckyorange.com)) for the purpose of web analysis and to operate the live chat system, which serves to answer live support inquiries. Anonymized user profiles can be created from this data using a pseudonym. Cookies may be used for this purpose. Cookies are small text files that are stored locally in the cache of the site visitor's internet browser. The cookies enable the recognition of the internet browser. The data collected with Lucky Orange technologies will not be used to personally identify the visitor to this website without the separately granted consent of the person concerned and will not be combined with personal data about the holder of the pseudonym. If the information collected this way has a personal reference, the processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in effective customer service and the statistical analysis of user behavior for optimization purposes.
To avoid the storage of Lucky Orange cookies, you can set your internet browser so that no more cookies can be stored on your computer in the future or already stored cookies are deleted. Disabling all cookies may result in some functions on our websites not being executable. You can object to the collection and storage of data for the creation of a pseudonymized user profile at any time with future effect by sending us your objection informally via email to the email address stated in the imprint.
Alternatively, you can object to the collection of data by Lucky Orange for the future by having an opt-out cookie set, which you can download from the following website: [Lucky Orange Privacy Policy](https://www.luckyorange.com/privacy.php). Please do not delete this opt-out cookie as long as you want to maintain your objection.
**5.2 Review Reminder by Loox**
If you have given us your express consent to do so during or after your order, we will send your email address and, if applicable, other customer data previously collected to the review tool Loox, a service of Loox Online Ltd., Rehov Har Sinai 2, 6581602 Tel Aviv-Yafo, Israel ("Loox"), so that they can send you a review reminder via email. You can withdraw your consent at any time by sending a message to the data controller or to the review platform.
For the transfer of data to Loox in Israel, the appropriate level of data protection is guaranteed by an adequacy decision of the European Commission. We have entered into a data processing agreement with Loox, in which we obligate Loox to protect our customers' data and not to disclose it to third parties. You can view this agreement here: [Loox Data Processing Agreement](https://loox.io/legal/data_processing_addendum.pdf). More information about Loox's privacy policy can be found here: [Loox Privacy Policy](https://loox.io/legal/privacy_policy_merchants.pdf).
**5.3 Review Reminder by Trustpilot**
If you have given us your express consent to do so during or after your order, we will send your email address to the Trustpilot review platform, Trustpilot A/S, Pilestræde 58, 1112 Copenhagen K, Denmark ([www.trustpilot.com](https://www.trustpilot.com)), so that they can send you a review reminder via email. You can withdraw your consent at any time by sending a message to the data controller or to the review platform.
**5.4 Contacting Us**
When contacting us (e.g., via contact form or email), personal data is processed solely for the purpose of handling and responding to your inquiry and only to the extent necessary. The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Art. 6 para. 1 lit. f GDPR. If your contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted once the matter has been fully resolved and there are no legal retention obligations to the contrary.
**5.5 WhatsApp Business**
We offer visitors to our website the opportunity to contact us via the WhatsApp messaging service from WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. We use the so-called "Business Version" of WhatsApp for this purpose.
If you contact us via WhatsApp in the context of a specific transaction (e.g., a placed order), we will store and use the mobile number you use for WhatsApp and, if provided, your first and last name, in accordance with Art. 6 para. 1 lit. b GDPR to process and respond to your inquiry. Based on the same legal basis, we may request additional data (order number, customer number, address, or email address) via WhatsApp to be able to assign your request to a specific transaction.
If you use our WhatsApp contact for general inquiries (e.g., regarding services, availability, or our website), we will store and use the mobile number you use for WhatsApp and, if provided, your first and last name in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in providing the requested information efficiently and promptly.
Your data will always be used only to respond to your inquiry via WhatsApp. There is no disclosure to third parties.
Please note that WhatsApp Business gains access to the address book of the mobile device we use for this purpose and automatically transfers phone numbers stored in the address book to a server of the parent company Meta Platforms Inc. in the USA. We use a mobile device for operating our WhatsApp Business account in which only the WhatsApp contact details of those users are stored who have also contacted us via WhatsApp.
This ensures that any person whose WhatsApp contact details are stored in our address book has already consented to the transfer of their WhatsApp phone number from the address books of their chat contacts in accordance with Art. 6 para. 1 lit. a GDPR by accepting the WhatsApp terms of use upon initial use of the app on their device. The transmission of data of users who do not use WhatsApp and/or have not contacted us via WhatsApp is excluded.
The purpose and scope of data collection and the further processing and use of data by WhatsApp as well as your related rights and settings options for protecting your privacy can be found in WhatsApp's privacy policy: [WhatsApp Privacy Policy](https://www.whatsapp.com/legal/?eea=1#privacy-policy).
### 6) Data Processing When Opening a Customer Account
According to Art. 6 para. 1 lit. b GDPR, personal data will continue to be collected and processed if you provide it to us when opening a customer account. The data required for opening an account can be found in the input form on our website. Deleting your customer account is possible at any time and can be done by sending a message to the above address of the responsible party. After deleting your customer account, your data will be deleted as long as all contracts concluded through it have been fully processed, no legal retention periods exist, and there is no legitimate interest in further storage on our part.
### 7) Comment Function
When using the comment function on this website, information on the time the comment was created and the name of the commenter you have chosen will be stored and published on the website along with your comment. Additionally, your IP address will be stored for security reasons to enable assigning the author in case of illegal comments. Your email address will be stored for contacting you if a third party objects to your published content as illegal.
### 8) Use of Customer Data for Direct Advertising
**8.1 Subscription to Our Email Newsletter**
If you subscribe to our email newsletter, we will regularly send you information about our offers. The only required information for sending the newsletter is your email address. The provision of additional data is voluntary and is used to address you personally. For sending the newsletter, we use the so-called double opt-in procedure, which ensures that you only receive newsletters after you have explicitly confirmed your consent by clicking on a verification link sent to the specified email address.
By activating the confirmation link, you consent to the use of your personal data in accordance with Art. 6 para. 1 lit. a GDPR. When subscribing to the newsletter, we store your IP address entered by your Internet service provider (ISP) as well as the date and time of registration to be able to trace any potential misuse of your email address at a later date. The data collected when subscribing to the newsletter will be used exclusively for the intended purpose. You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending a message to the responsible party named at the beginning. After unsubscribing, your email address will be immediately deleted from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use your data in ways permitted by law and of which we inform you in this policy.
**8.2 Email Newsletter for Existing Customers**
If you have provided us with your email address during the purchase of goods or services, we reserve the right to regularly send you offers for similar goods or services from our range by email. For this purpose, we do not need to obtain separate consent from you under Section 7 para. 3 UWG. The data processing is solely based on our legitimate interest in personalized direct advertising in accordance with Art. 6 para. 1 lit. f GDPR. If you have initially objected to the use of your email address for this purpose, we will not send any emails. You can object to the use of your email address for the aforementioned advertising purposes at any time with effect for the future by sending a message to the responsible party named at the beginning. You will only incur transmission costs according to the base rates. After receiving your objection, the use of your email address for advertising purposes will cease immediately.
**8.3 Email Newsletter via Klaviyo**
The email newsletter is sent through the technical service provider "Klaviyo," 225 Franklin St, Boston, MA 02110, USA ([http://www.klaviyo.com](http://www.klaviyo.com)), to whom we transmit the data provided when subscribing to the newsletter. This disclosure takes place in accordance with Art. 6 para. 1 lit. f GDPR and serves our legitimate interest in using an effective, secure, and user-friendly newsletter system. Please note that your data is usually transmitted to a Klaviyo server in the USA and stored there.
Klaviyo uses this information to send and evaluate the newsletter on our behalf. Klaviyo does not use the data of our newsletter recipients to write to them themselves or pass them on to third parties.
To protect your data in the USA, we have entered into a data processing agreement ("Data Processing Agreement") with Klaviyo, in which Klaviyo commits to protecting the data of our users, to process it on our behalf according to its privacy policy, and in particular not to pass it on to third parties. You can view this agreement here: [Klaviyo Privacy Policy](https://www.klaviyo.com/privacy).
**8.4 Email Availability Notifications**
For temporarily unavailable items, you can subscribe to email notifications for product availability. We will send you an email notification once about the availability of the respective item you selected. The only required information for sending this notification is your email address. Providing additional data is voluntary and may be used to address you personally. We use the so-called double opt-in procedure to ensure that you only receive a notification if you have explicitly confirmed your consent by clicking on a verification link sent to the specified email address.
By activating the confirmation link, you consent to the use of your personal data in accordance with Art. 6 para. 1 lit. a GDPR. When registering for our email notification service for product availability, we store your IP address entered by your Internet service provider (ISP) as well as the date and time of registration to be able to trace any potential misuse of your email address at a later date. The data collected when subscribing to our email notification service will be used exclusively for the intended purpose. You can unsubscribe from the availability notifications at any time by sending a message to the responsible party named at the beginning. After unsubscribing, your email address will be immediately deleted from our dedicated distribution list unless you have expressly consented to further use of your data or we reserve the right to use your data in ways permitted by law and of which we inform you in this policy.
### 9) Data Processing for Order Handling
**9.1 Transmission of Image Files for Order Handling via Upload Function**
We offer customers the opportunity to commission the personalization of products by submitting image files via an upload function on our website. The uploaded image is used as a template for the personalization of the selected product.
The upload form on the website allows customers to transmit one or more image files from the storage of the used device directly to us via automated, encrypted data transfer. We capture, store, and use the transmitted files exclusively for creating the personalized product as described on our website. If the uploaded image files are shared with specific service providers for production and order handling, this will be explicitly stated in the following sections. There is no further sharing beyond this. If the transmitted files or digital images contain personal data (especially images of identifiable persons), all of the mentioned processing operations are carried out solely for the purpose of handling your online order in accordance with Art. 6 para. 1 lit. b GDPR. After the order is fully processed, the transmitted image files will be automatically and completely deleted.
**9.2 Transfer of Personal Data to Fulfillment Partners**
To fulfill our contractual obligations to our customers, we work with external shipping partners. We share your name, delivery address, and, if necessary, your telephone number exclusively for delivery purposes under Art. 6 para. 1 lit. b GDPR with a shipping partner selected by us.
**9.3 Payment Service Providers**
- **PayPal**
For payments via PayPal, credit card via PayPal, direct debit via PayPal, or – if offered – "purchase on account" or "installment payment" via PayPal, we share your payment data with PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg ("PayPal") as part of the payment processing. The data transfer is carried out in accordance with Art. 6 para. 1 lit. b GDPR and only to the extent necessary for the payment processing.
PayPal reserves the right to conduct a credit check for the payment methods credit card via PayPal, direct debit via PayPal, or – if offered – "purchase on account" or "installment payment" via PayPal. For this purpose, your payment data may be shared with credit agencies under Art. 6 para. 1 lit. f GDPR based on PayPal's legitimate interest in determining your solvency. PayPal uses the result of the credit check concerning the statistical probability of default to decide whether to provide the respective payment method. The credit report may contain probability values (so-called score values). If score values are included in the credit report result, they are based on a scientifically recognized mathematical-statistical procedure. Address data is included in the calculation of score values among other factors. For further information on data protection, including the credit agencies used, please refer to PayPal's privacy policy: [PayPal Privacy Policy](https://www.paypal.com/de/webapps/mpp/ua/privacy-full). You may object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if necessary for contractual payment processing.
- **Shopify Payments**
We use the payment service provider "Shopify Payments," 3rd Floor, Europa House, Harcourt Building, Harcourt Street, Dublin 2. If you choose a payment method offered by Shopify Payments, the payment processing is carried out through the technical service provider Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, to whom we share your information provided during the order process, including details about your order (name, address, account number, bank code, possibly credit card number, invoice amount, currency, and transaction number) in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data is carried out solely for the purpose of processing payments with Stripe Payments Europe Ltd. and only to the extent necessary for this purpose. More information on Shopify Payments' privacy policy can be found here: [Shopify Privacy Policy](https://www.shopify.com/legal/privacy). Data protection information for Stripe Payments Europe Ltd. can be found here: [Stripe Privacy Policy](https://stripe.com/de/privacy).
### 10) Online Marketing
**Google Ads Remarketing**
Our website uses the functions of Google Ads Remarketing, which we use to advertise for this website in Google search results and on third-party websites. The provider is Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). For this purpose, Google sets a cookie in the browser of your device, which automatically enables interest-based advertising based on the pages you have visited using a pseudonymous cookie ID. Further data processing only takes place if you have consented to Google linking your internet and app browsing history to your Google account and using information from your Google account to personalize ads you view on the web. If you are logged in to Google during your visit to our website, Google uses your data together with Google Analytics data to create and define audience lists for cross-device remarketing. Your personal data may also be temporarily linked to Google Analytics data for audience formation. Within the use of Google Ads Remarketing, there may also be a transfer of personal data to Google LLC servers in the USA.
**Facebook Pixel for the Creation of Custom Audiences with Advanced Data Matching (with Cookie Consent Tool)**
Within our online offerings, we use the so-called "Facebook Pixel" from the social network Facebook, operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland ("Facebook"). Based on your explicit consent, when a user clicks on an advertisement we place on Facebook, the URL of our linked page is appended by the Facebook Pixel. This URL parameter is then recorded in the user's browser via a cookie set by our linked page. Additionally, this cookie captures specific customer data such as email addresses that we collect on our linked page during transactions such as purchases, account logins, or registrations (advanced data matching). The cookie is then read by the Facebook Pixel and enables the forwarding of data, including specific customer data, to Facebook.
With the help of the Facebook Pixel with advanced data matching, Facebook can precisely identify visitors to our online offering as a target audience for displaying ads (so-called "Facebook Ads"). Accordingly, we use the Facebook Pixel with advanced data matching to display the Facebook Ads we place only to Facebook users who have shown interest in our online offering or exhibit specific characteristics (e.g., interests in certain topics or products determined by the pages visited) that we convey to Facebook (so-called "Custom Audiences"). With the help of the Facebook Pixel with advanced data matching, we also want to ensure that our Facebook Ads correspond to users' potential interests and do not appear intrusive. Thus, we can further evaluate the effectiveness of Facebook ads for statistical and market research purposes by tracking whether users were directed to our website after clicking on a Facebook ad (so-called "conversion"). Compared to the standard version of Facebook Pixel, the function of advanced data matching helps us better measure the effectiveness of our advertising campaigns by capturing more attributed conversions.
All transmitted data is stored and processed by Facebook, allowing a connection to the respective user profile and enabling Facebook to use the data for its advertising purposes, according to Facebook's data use policy ([https://www.facebook.com/about/privacy/](https://www.facebook.com/about/privacy/)). The data may enable Facebook and its partners to serve ads on and off Facebook.
These processing operations occur only upon explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. The information generated by Facebook is generally transmitted to a server of Facebook and stored there, and may also be transmitted to the servers of Meta Platforms Inc. in the USA. You can withdraw your consent at any time with future effect by deactivating this service in the "Cookie Consent Tool" provided on the website.
### 11) Web Analysis Services
**Google (Universal) Analytics**
This website uses Google (Universal) Analytics, a web analysis service of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). Google (Universal) Analytics uses so-called "cookies," which are text files stored on your device that allow analysis of your use of the website. The information generated by the cookie about your use of this website (including the truncated IP address) is generally transmitted to a Google server and stored there, and may also be transferred to Google LLC servers in the USA.
This website uses Google (Universal) Analytics exclusively with the "_anonymizeIp()" extension, which ensures anonymization of the IP address by truncation and excludes direct personal reference. By this extension, your IP address is truncated by Google within member states of the European Union or in other contracting states of the agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google LLC server in the USA and truncated there. On our behalf, Google will use this information to evaluate your use of the website, to compile reports on website activities, and to provide additional services related to website use and internet use. The IP address transmitted by your browser within the scope of Google (Universal) Analytics will not be merged with other data from Google.
Google Analytics allows the creation of statistics regarding age, gender, and interests of site visitors based on an evaluation of interest-related advertising and third-party information through a special function known as "demographic features." This allows for the definition and differentiation of user groups of the website for the purpose of target group-optimized marketing measures. However, the datasets collected through the "demographic features" cannot be attributed to specific individuals.
Details about the processing initiated by Google Analytics and how Google handles data from websites can be found here: [Google Policies](https://policies.google.com/technologies/partner-sites). All the processing described above, especially the setting of Google Analytics cookies to read information on the used device, only takes place if you have explicitly consented to it in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, Google Analytics will not be used during your visit to the site. You can withdraw your consent at any time with future effect. To exercise your withdrawal, please deactivate this service in the "Cookie Consent Tool" provided on the website. We have concluded a data processing agreement with Google for the use of Google Analytics, obligating Google to protect the data of our site visitors and not to pass it on to third parties. For the transfer of data from the EU to the USA, Google relies on so-called standard contractual clauses of the European Commission, which aim to ensure compliance with the European level of data protection. More information on Google (Universal) Analytics can be found here: [Google Privacy Policy](https://policies.google.com/privacy?hl=de&gl=de).
### 12) Retargeting/Remarketing/Recommender Advertising
**Google Ads Remarketing**
Our website uses the functions of Google Ads Remarketing to advertise for this website in Google search results and on third-party websites. The provider is Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). To this end, Google sets a cookie in your device's browser, which automatically enables interest-based advertising based on the pages you have visited using a pseudonymous cookie ID. Further data processing only takes place if you have consented to Google linking your internet and app browsing history to your Google account and using information from your Google account to personalize ads you view on the web. If you are logged in to Google during your visit to our website, Google uses your data together with Google Analytics data to create and define audience lists for cross-device remarketing. Your personal data may also be temporarily linked to Google Analytics data for audience formation. Within the use of Google Ads Remarketing, there may also be a transfer of personal data to Google LLC servers in the USA.
**Pinterest Retargeting Pixel**
This website integrates a pixel (Pinterest Tag) from Pinterest Europe Ltd. (Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland) ("Pinterest"). Using the pixel, information about the browsing behavior of website visitors is collected, stored, and evaluated in pseudonymized form. The information can be assigned to the user using additional information that Pinterest has stored about the user due to their account on the social network "Pinterest." Pinterest analyzes browsing behavior using an algorithm and can then display targeted product recommendations as personalized advertising banners on the user's Pinterest account. Pinterest may also combine the information collected via the pixel with information collected by Pinterest from other websites and/or in connection with the use of the social network "Pinterest" to create pseudonymized usage profiles. In no case can the information collected be used to personally identify visitors to this website.
### 13) Page Functionalities
**13.1 Use of YouTube Videos**
This website uses the YouTube embedding feature to display and play videos from the provider "YouTube," which belongs to Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland. The extended privacy mode is used here, which according to the provider's information activates the storage of user information only when the videos are played. When embedded YouTube videos are played, the provider "YouTube" uses cookies to collect information about user behavior. According to "YouTube," these are used, among other things, to collect video statistics, improve user-friendliness, and prevent abusive behavior. If you are logged into Google, your data is directly assigned to your account when you click on a video. If you do not want the assignment to your profile at YouTube, you must log out before activating the button. You have the right to object to the formation of these user profiles, for which you must contact YouTube. Using YouTube may also result in the transmission of personal data to the servers of Google LLC in the USA.
**13.2 Use of Vimeo Videos**
Our website integrates plugins from the video portal Vimeo, LLC, 555 West 18th Street, New York, New York 10011, USA. When you access a page of our website that contains such a plugin, your browser establishes a direct connection to the Vimeo servers. The content of the plugin is sent directly from Vimeo to your browser and embedded in the page. This integration allows Vimeo to know that your browser has accessed the corresponding page of our website, even if you do not have a Vimeo account or are not logged into Vimeo at that moment. This information (including your IP address) is sent directly from your browser to a Vimeo server in the USA and stored there.
If you are logged into Vimeo, it can assign the visit of our website directly to your Vimeo account. If you interact with the plugins (such as clicking the play button of a video), this information is also sent directly to a Vimeo server and stored there.
If you do not want Vimeo to assign the data collected through our website directly to your Vimeo account, you must log out of Vimeo before visiting our website.
For the purpose and scope of data collection and the further processing and use of the data by Vimeo as well as your rights and options for protecting your privacy, please refer to Vimeo's privacy policy: [Vimeo Privacy Policy](https://vimeo.com/privacy).
### 14) Tools and Miscellaneous
**Cookie Consent Tool**
This website uses a so-called "Cookie Consent Tool" to obtain valid user consent for consent-required cookies and cookie-based applications. The "Cookie Consent Tool" is displayed to users when accessing the site in the form of an interactive user interface, where consents for specific cookies and/or cookie-based applications can be given by checking boxes. With the use of the tool, all consent-required cookies/services are only loaded if the respective user has granted corresponding consent by checking the boxes. This ensures that only if consent is given are such cookies set on the user's device.
The tool technically sets necessary cookies to store your cookie preferences. Personal user data is generally not processed in this regard.
If, in individual cases, personal data (such as IP address) is processed for the purpose of storing, assigning, or logging cookie settings, this is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in a legally compliant, user-specific, and user-friendly consent management for cookies and thus a legally compliant design of our internet presence. Another legal basis for processing is also Art. 6 para. 1 lit. c GDPR. As responsible parties, we are legally obligated to make the use of technically unnecessary cookies dependent on user consent.
Further information on the operator and the settings of the Cookie Consent Tool can be found directly in the corresponding user interface on our website.
### 15) Rights of the Affected Person
15.1 Applicable data protection law grants you the following rights against the responsible party regarding the processing of your personal data (information and intervention rights), whereby the respective conditions for exercising these rights refer to the cited legal basis:
- Right to information according to Art. 15 GDPR;
- Right to correction according to Art. 16 GDPR;
- Right to deletion according to Art. 17 GDPR;
- Right to restriction of processing according to Art. 18 GDPR;
- Right to notification according to Art. 19 GDPR;
- Right to data portability according to Art. 20 GDPR;
- Right to withdraw granted consents according to Art. 7 para. 3 GDPR;
- Right to lodge a complaint according to Art. 77 GDPR.
15.2 **Right to Object**
IF WE PROCESS YOUR PERSONAL DATA BASED ON A BALANCING OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THIS PROCESSING WITH FUTURE EFFECT.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE RELEVANT DATA. FURTHER PROCESSING REMAINS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR IF THE PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.
IF WE PROCESS YOUR PERSONAL DATA FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING. YOU CAN EXERCISE THE RIGHT TO OBJECT AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE RELEVANT DATA FOR DIRECT MARKETING PURPOSES.
### 16) Duration of Storage of Personal Data
The duration of the storage of personal data is determined by the respective legal basis, the purpose of processing, and, where applicable, the respective statutory retention period (e.g., commercial and tax retention periods).
When processing personal data on the basis of explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, this data will be stored until the affected person withdraws their consent.
If there are legal retention periods for data processed in the context of contractual or similar obligations based on Art. 6 para. 1 lit. b GDPR, this data will be routinely deleted after the expiration of the retention periods, unless it is no longer necessary for fulfilling the contract or initiating a contract and/or there is no legitimate interest in further storage on our part.
When processing personal data based on Art. 6 para. 1 lit. f GDPR, this data will be stored until the affected person exercises their right to object under Art. 21 para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the affected person, or the processing serves the establishment, exercise, or defense of legal claims.
When processing personal data for direct marketing purposes based on Art. 6 para. 1 lit. f GDPR, this data will be stored until the affected person exercises their right to object under Art. 21 para. 2 GDPR.
Unless otherwise stated in the additional information in this statement regarding specific processing situations, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.