Privacy Policy

1. Controller and Data Protection Officer

The controller responsible for the processing of personal data on this website and in the VIU online shop is:

VIU Ventures AG Räffelstrasse 24 CH-8045 Zürich Switzerland

E-mail: hello@shopviu.com

The Data Protection Officer can be contacted at:

Proliance GmbH

www.proliance.ai

Data Protection Officer

Leopoldstr. 21

80802 Munich

E-mail: datenschutzbeauftragter@proliance.ai

2. Scope and general information

This privacy notice provides information about the processing of personal data in connection with the use of the website shopviu.com, including the German-language shop pages, the VIU online shop, store appointment booking, contacting us, sending the newsletter, and the embedded services used on the website, as well as the personal data collected in the stores.

Personal data is any information relating to an identified or identifiable natural person. We process personal data only in accordance with the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), the Telecommunications-Digital Services-Data Protection Act (TDDDG) and any other applicable data protection provisions.

3. Accessing the website and server log data

When you access our website, technically necessary data is processed so that the website can be delivered, operated securely and protected against attacks. This may include in particular:

  • IP address and time of access
  • the URL accessed and the referrer URL
  • the volume of data transferred and the HTTP status code
  • browser type, browser version, operating system and language settings
  • technical device and connection data as well as error and security information

This processing takes place to safeguard our legitimate interest in a secure, stable and functional online offering, on the basis of Art. 6(1)(f) GDPR. Insofar as information is stored on or read from the terminal device, Section 25(2) no. 2 TDDDG is additionally applicable, to the extent this is technically strictly necessary.

Hosting and Google Cloud Services:

We host our website, our online shop and the associated systems in part via Google Cloud Services. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

In connection with hosting, the following data may in particular be processed: IP address and technical access data, date and time of access, content and URLs accessed, browser, device and operating system data, error and security information, as well as data from customer accounts, orders, deliveries, returns and customer communications, insofar as this is necessary for the operation and handling of the online shop.

This processing takes place for the purpose of providing our website and our online shop securely, stably and in working order, and for performing and handling contractual relationships. The legal bases are Art. 6(1)(b) GDPR, insofar as the processing is necessary for the performance of a contract or pre-contractual measures, Art. 6(1)(c) GDPR, insofar as legal obligations are concerned, and Art. 6(1)(f) GDPR. Our legitimate interest lies in particular in the secure and reliable provision of our digital offerings.

In the context of the cloud services we use, Google generally processes the data as a processor on the basis of a data processing agreement (DPA) pursuant to Art. 28 GDPR. Under our current configuration, the primary storage of the data processed in connection with hosting takes place within the European Union. However, processing or access from third countries cannot be ruled out in connection with individual support, security or infrastructure services. Insofar as personal data is transferred to Google LLC in the USA, we rely on Google LLC's certification under the EU-U.S. Data Privacy Framework pursuant to Art. 45 GDPR. Insofar as this basis does not apply, appropriate safeguards under Art. 46 GDPR are used.

Insofar as personal data is transferred to third countries, this takes place only under the conditions set out in Art. 44 et seq. GDPR. Appropriate safeguards used may include, in particular, the Standard Contractual Clauses (SCCs) issued by the European Commission together with supplementary technical and organisational measures. Further information on the safeguards and recipients used in each case can be found in the section „Transfer of data to third countries“.

Technical server and security logs are stored only for as long as necessary for secure operation, error analysis and the prevention of attacks. Statutory retention obligations and longer storage periods within backup copies remain unaffected.

Further information on data protection at Google can be found at: https://policies.google.com/privacy?hl=de

4. Content delivery network and web server security

Cloudflare CDN

We use Cloudflare as an upstream content delivery network for the fast and secure delivery of our website and to protect against abusive access and attacks. In doing so, IP address, timestamp, requested content, browser and device information, as well as technical security data may in particular be processed. The provider is Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich, Germany. Cloudflare processes the data as a processor on the basis of a data processing agreement (DPA) pursuant to Art. 28 GDPR. Cloudflare operates servers worldwide; processing outside the EEA can therefore not be ruled out. Insofar as data is transferred to the USA, we rely on the certification of Cloudflare, Inc. under the EU-U.S. Data Privacy Framework (Art. 45 GDPR). The legal basis is Art. 6(1)(f) GDPR. Further information: https://www.cloudflare.com/de-de/trust-hub/gdpr/

We use the content delivery network (CDN) of Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107 USA (Cloudflare) in order to increase the security and delivery speed of our website. A content delivery network is an online service by means of which, in particular, large media files (such as graphics, page content or scripts) are delivered through a network of regionally distributed servers connected via the internet. For this purpose, the browser you use must establish a connection to Cloudflare's servers. As a result, Cloudflare becomes aware that our website was accessed via your IP address. The data generated in this process is used only for the aforementioned purpose and to maintain the functionality and security of the CDN. For this purpose, personal data may be processed by Cloudflare in the form of server log files. The server log files may store the name of the web page or file retrieved, the date and time of retrieval, the volume of data transferred, a message indicating successful retrieval, the browser type and version, the user's operating system, referrer URL (the previously visited page), IP address and the requesting provider. This data also helps Cloudflare, for example, to identify new threats to websites. In this way, Cloudflare can ensure a high level of security protection for our website.

The processing of personal data in connection with the use of Cloudflare takes place on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR in increasing the security and delivery speed of our website.

In general, Cloudflare stores data at user level for domains on the Free, Pro and Business plans for less than 24 hours. Cloudflare retains server log files only for as long as necessary, and in most cases this data is deleted again within 24 hours. However, there is also information that Cloudflare stores indefinitely as part of its permanent logs, in order to improve Cloudflare's overall performance and identify any security risks. You can find out exactly which permanent logs are stored at https://developers.cloudflare.com/1.1.1.1/commitment-to-privacy/privacy-policy/privacy-policy/. According to Cloudflare, all data that Cloudflare permanently collects is stripped of personal data and is therefore anonymised.

Data is transferred to Cloudflare Inc., based in the USA. For the USA, an adequacy decision of the EU Commission exists pursuant to Art. 45(1) GDPR in respect of companies certified under the EU-U.S. Data Privacy Framework. Cloudflare Inc. is certified under the EU-U.S. Data Privacy Framework and thereby undertakes to comply with appropriate data protection standards, which can be verified at the following link: Participant Search (dataprivacyframework.gov).

We have concluded a data processing agreement (DPA) with Cloudflare.

More detailed information on data protection and Cloudflare is available at: https://www.cloudflare.com/de-de/gdpr/introduction/ and https://www.cloudflare.com/privacypolicy/

Cloudflare Turnstile

We use Cloudflare Turnstile to detect and prevent automated access, in particular to protect forms and other functions from abusive use. In doing so, technical information about the browser, device, IP address, connection data and usage activities may be processed. This processing is necessary for the security and operational functionality of the respective function and takes place on the basis of Art. 6(1)(f) GDPR. Insofar as information is stored on or read from the terminal device for this purpose, Section 25(2) no. 2 TDDDG is applicable. The provider is Cloudflare, Inc. and/or Cloudflare Germany GmbH. Insofar as data is transferred to the USA, we rely on the certification of Cloudflare, Inc. under the EU-U.S. Data Privacy Framework (Art. 45 GDPR). Further information: https://www.cloudflare.com/privacypolicy/

5. Consent management, cookies and similar technologies

Consent management

To manage and document your consents, we use Cookiebot, a service provided by Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark. Cookiebot stores the consent status you have selected as well as the technical details required to demonstrate consent. This may in particular include an anonymised IP address, browser information, the web address accessed, and the date and time of consent. The consent data is stored for twelve months and subsequently deleted or anonymised, unless it needs to be retained for longer as evidence for legal reasons. The legal basis for documenting consent is Art. 6(1)(c) GDPR. Insofar as consent management stores information on or reads information from the terminal device, this takes place pursuant to Section 25(2) no. 2 TDDDG, to the extent this is strictly necessary for consent management. Further information: https://www.cookiebot.com/de/privacy-policy/

Cookies and similar technologies

Cookies are small text files or comparable pieces of information that can be stored on, or read from, your terminal device. They make it possible, for example, to save settings, to technically ensure the operation of a website, to statistically evaluate the use of a website, or to make content and advertising more relevant to your interests.

In addition to cookies, other comparable technologies may also be used. These include, for example, local storage, session storage, pixels, tags or comparable identifiers. These technologies can store information on your terminal device or read information already stored on your terminal device. Depending on the technology used, technical information about your terminal device, your browser, your use of the website and your interactions may also be processed.

We distinguish in particular between the following categories:

  • Technically necessary cookies and similar technologies:These technologies are necessary for the operation, security and basic functions of our website. They enable, for example, page navigation, the shopping basket function, the ordering process, session management, appointment booking, the storage of your consent settings, and protection against abusive access. Without these technologies, the website may not be usable in full, or not usable securely.
  • Preference and convenience technologies:These technologies store settings you have selected, such as language, region, the presentation of the website, or certain usability settings. Insofar as these technologies are not technically strictly necessary, they are used only with your consent.
  • Analytics and statistics technologies:These technologies help us to understand how our website is used and to improve its functions, content and user-friendliness. In doing so, page views, clicks, interactions, device and browser information, as well as information on the origin of access, may for example be processed. Analytics and statistics technologies are used only with your consent.
  • Marketing and advertising technologies:These technologies may be used to measure the success of advertising campaigns, to form target groups, to serve interest-based advertising, or to statistically evaluate its delivery and success. In doing so, cookie and device identifiers, online identifiers, interactions, device and browser information, as well as information on pages visited, may among other things be processed. Marketing and advertising technologies are used only with your consent.
  • Technologies for external content and media:These technologies may be necessary to embed external content such as maps, videos, fonts, images or other media. When retrieving such content, technical data, in particular your IP address, browser and device information, and information on the content requested, may be transmitted to the respective provider. Insofar as the embedding is not technically strictly necessary, it takes place only with your consent.

Insofar as cookies or similar technologies are technically strictly necessary for the operation of the website, the storage of, or reading of, information on your terminal device takes place on the basis of Section 25(2) no. 2 TDDDG. For cookies and similar technologies that are not strictly necessary, we obtain your consent in advance pursuant to Section 25(1) TDDDG. The subsequent processing of personal data is based, where necessary, on Art. 6(1)(a) GDPR.

You may withdraw or change your consent at any time with effect for the future via the cookie settings. The lawfulness of the processing carried out up to the withdrawal remains unaffected. The cookie settings also allow you to view which categories, providers, purposes and storage periods apply to the respective cookies and similar technologies used.

Cookies can also be distinguished according to how long they are stored:

  • Session cookies are stored only for the duration of your visit to our website and are deleted when you close your browser.
  • Persistent cookies remain stored on your terminal device for a specified period, or until you delete them yourself. The respective storage period depends on the specific cookie or the technology used.

6. Analytics, marketing and conversion

Google Analytics

On our web pages, we embed the service „Google Analytics“ provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA.

In the European Union (EU) and the European Economic Area (EEA), the service is offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Description of the data processing and its purpose

„Google Analytics“ creates usage profiles based on pseudonyms (recognition features derived from cookie and device IDs and further data on the terminal device used, or the so-called browser fingerprint) and usage data (e.g. name and address of the web page content requested by your browser, referral links, a description of the web browser and operating system used, and the IP address of the requesting terminal device).

Likewise,

  • demographic data (such as continent, country, region, city, age bracket, gender, language and interests of users)
  • data on your interactions with search engines or other websites, as recorded by Google (such as queries in search engines that can be linked to your Google account, the origin of your visit to our page, i.e. whether it resulted, for example, from clicking a paid advertisement in a search engine, search terms used, or, as the case may be, the history of websites you have visited)
  • information on the website through which you arrived at our website,
  • information on your terminal device (such as category, manufacturer and model) and its configuration (e.g. language settings, screen resolution),
  • information on your interests, insofar as these are recorded by Google in connection with your internet use,
  • information on your interactions with our advertisements and/or campaigns, e.g. that a specific action on our website can be attributed to clicking on a particular advertisement,
  • data on your interactions with our web pages and our online shop (in particular login status, customer number, status as a commercial customer or consumer, past visits to our website, subpages accessed, data on the timing of visits and the duration of sessions, button clicks, scroll depth, read depth, as well as the use of filters, search actions, forms and other input and log-in options, links clicked to external websites/files, data on products and services viewed or purchased by you on our web pages, data on use of the shopping basket as well as completed and uncompleted purchase transactions, data on your revenue) as well as
  • data on your interactions with social media networks (such as the sharing of content).

are collected and analysed.

In this way, Google is able to pseudonymously recognise website visitors and the terminal devices they use, count them as such, and assign them to particular demographic target groups, interest groups or customer segments.

Visitors who have their own user account on Google platforms can additionally be identified by Google across devices as visitors to our web pages.

Cookies and similar techniques, in particular JavaScript, are used to store and read data on your terminal device. Further details can be found above under „Data processing in connection with cookies and similar techniques“.

From the information processed, Google creates aggregated statistics for us, from which we can identify what our website users are interested in and how many users interacted with our web pages, and in what way.

We receive from Google only aggregated statistics (aggregated data), from which we, as a user of Google's advertising services, cannot draw any conclusions about individual persons.

We subsequently use these insights to place targeted online advertising measures and marketing campaigns in advertising networks, in particular in Google's advertising services.

The purpose of the data processing is to enable us to evaluate and analyse the origin, preferences and interests of visitors to our web pages, so that we can subsequently optimise our online advertising measures and serve advertisements in a manner precisely targeted at particular audiences, on the basis of these insights.

Legal basis for the data processing

The legal basis for embedding and using the service is your consent, provided you have given it via our consent management platform.

The use of cookies and similar technologies takes place on the basis of Section 25(1) TDDDG. The subsequent data processing is based on Art. 6(1) sentence 1(a) GDPR.

Your consent is voluntary and may be freely withdrawn at any time with effect for the future. To exercise your withdrawal, please use the „cookie settings“ link at the bottom of the web page to call up the consent management platform again and change your settings.

Recipients

In connection with the use of the services, the data collected via our web pages is transferred to the following recipients:

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland,
  • Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA.

Further information on the handling of personal data by the provider of the service can be found at https://policies.google.com/privacy?hl=de.

Data processing in third countries

Your data is transferred to recipients in third countries. For transfers of data to the USA, an adequacy decision of the EU Commission exists in respect of undertakings certified under the EU-U.S. Data Privacy Framework. Google LLC is certified under the EU-U.S. Data Privacy Framework.

Storage period

By integrating the service on our websites, data is transferred to the recipients named above and stored there for a period of 14 months. The data processed by the service and made available to us is not stored beyond this in our own systems.

Google Tag Manager

On our websites we integrate the service “Google Tag Manager” of Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA.

In the European Union (EU) and the European Economic Area (EEA), the service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Description of the data processing and purpose

“Google Tag Manager” is a tag management system (TMS) that enables us to integrate and manage further website content in JavaScript or HTML code.

In particular, this allows so-called tags to be integrated into and managed on our website. Tags are small code fragments or markers (web beacons, tracking pixels or similar markers) which enable services for website analysis or user tracking to distinguish between or identify users.

The analysis of website visits and user tracking are not carried out by “Google Tag Manager” itself, but by the services used for these purposes, such as “Google Analytics” or other third-party solutions. Rather, “Google Tag Manager” merely serves to integrate and manage the markers on our websites that are required for analysis or tracking.

As “Google Tag Manager” is provided by Google and is loaded from its servers when a page is called up, the usage data technically required for the page call-up is also transmitted in the process. In this respect, Google also receives your IP address, which is technically required to retrieve the content.

The purpose of the data processing and our legitimate interest lie in being able to integrate further services and content into our websites in a simple and efficient manner through the use of Google Tag Manager.

Legal basis for the data processing

The legal basis for the integration and use of the service is your consent, provided you have given this via our consent management platform.

The use of cookies and similar technologies is carried out on the basis of Section 25(1) TDDDG. The subsequent data processing is based on Art. 6(1)(a) GDPR.

Your consent is voluntary and may be withdrawn at any time with effect for the future. To exercise your withdrawal, please use the “Cookie settings” link at the bottom of the website to access the consent management platform again and change your settings.

Recipients

In the context of using the service, the data collected via our websites is transmitted to the following recipients:

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland,
  • Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA.

Further information on the handling of personal data by the provider of the service can be found at https://policies.google.com/privacy?hl=de.

Data processing in third countries

Your data is transferred to recipients in third countries. For transfers of data to the USA, an adequacy decision of the EU Commission exists in respect of undertakings certified under the EU-U.S. Data Privacy Framework. Google LLC is certified under the EU-U.S. Data Privacy Framework.

Storage period

By integrating the service on our websites, data is transmitted to the recipients named above and processed there for as long as is necessary to achieve the purposes stated. The data processed by the service and made available to us is not stored beyond this in our own systems.

Google Ads, Google Ads Conversion Tracking and Google Remarketing

We use the Google Ads service in order to draw attention to our attractive offers on external websites by means of advertisements (so-called Google Ads). By reference to the data from the advertising campaigns, we can determine how successful the individual advertising measures are. In doing so, we pursue the interest of showing you advertising that is of interest to you, making our website more interesting for you and achieving a fair calculation of advertising costs.

These advertisements are delivered by Google via so-called “ad servers”. For this purpose we use ad server cookies, by means of which certain parameters for measuring success, such as the display of advertisements or clicks by users, can be measured. If you reach our website via a Google advertisement, a cookie is stored on your PC by Google Ads. These cookies generally lose their validity after 30 days and are not intended to identify you personally. As analysis values, this cookie generally stores the unique cookie ID, the number of ad impressions per placement (frequency), the last impression (relevant for post-view conversions) and opt-out information (marking that the user no longer wishes to be addressed).

These cookies enable Google to recognise your internet browser. If a user visits certain pages of the website of an Ads customer and the cookie stored on their computer has not yet expired, Google and the customer can identify that the user clicked on the advertisement and was redirected to that page. In addition, information on transactions carried out online and offline in the shop (event data such as appointment bookings, purchases, shopping basket value) as well as your hashed e-mail address are transmitted to Google Ads for the purpose of measuring success. A different cookie is assigned to each Ads customer. Cookies therefore cannot be tracked across the websites of Ads customers. We ourselves do not collect or process any personal data as part of the advertising measures described. We only receive statistical evaluations from Google. On the basis of these evaluations, we can identify which of the advertising measures used are particularly effective. We do not receive any further data from the use of the advertisements, and in particular we cannot identify users on the basis of this information.

Due to the marketing tools used, your browser automatically establishes a direct connection with Google's server. We have no influence on the scope and further use of the data collected by Google through the use of this tool, and we therefore inform you in accordance with our level of knowledge: through the integration of Ads Conversion, Google receives the information that you have accessed the corresponding part of our website or clicked on an advertisement of ours. If you are registered with a Google service, Google can allocate the visit to your account. Even if you are not registered with Google or have not logged in, it is possible that the provider may obtain and store your IP address.

You can prevent participation in this tracking procedure in various ways: a) by means of a corresponding setting in your browser software; in particular, suppressing third-party cookies means that you will not receive advertisements from third-party providers; b) by deactivating cookies for conversion tracking by setting your browser so that cookies from the domain “www.googleadservices.com” are blocked, https://www.google.de/settings/ads, whereby this setting will be deleted if you delete your cookies; c) by deactivating the interest-based advertisements of providers that are part of the self-regulatory campaign “About Ads” via the link http://www.aboutads.info/choices, whereby this setting will be deleted if you delete your cookies; d) by permanently deactivating this in your Firefox, Internet Explorer or Google Chrome browsers via the link http://www.google.com/settings/ads/plugin. We would point out that in this case you may not be able to use all functions of this offer to their full extent.1

In addition to Ads Conversion, we use the Google Remarketing application. This is a procedure by which we seek to address you again. Through this application, after visiting our website, our advertisements may be displayed to you during your further use of the internet. This takes place by means of cookies stored in your browser, through which your usage behaviour when visiting various websites is recorded and evaluated by Google. In this way, Google can determine your previous visit to our website. According to Google's own statements, the data collected as part of remarketing is not combined by Google with your personal data that may be stored by Google. In particular, according to Google, pseudonymisation is used in remarketing.

The legal basis for the integration and use of Google Ads is Art. 6(1)(a) GDPR, and Section 25(1) TDDDG is also relevant for online visits to our website.

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Insofar as personal data is transmitted to Google LLC in the USA, we rely on the certification of Google LLC under the EU-U.S. Data Privacy Framework pursuant to Art. 45 GDPR. Further information: https://policies.google.com/technologies/ads?hl=de

You may withdraw your consent to the use of cookies and related technologies at any time with effect for the future.

Google AdSense

This website uses the online advertising service Google AdSense, through which advertising tailored to your interests may be presented to you. In doing so, we pursue the interest of showing you advertising that may be of interest to you, in order to make our website more interesting for you. For this purpose, statistical information about you is collected and processed by our advertising partners. These advertisements are recognisable by the notice “Google Ads” in the respective advertisement.

By visiting our website, Google receives the information that you have accessed our website. For this purpose, Google uses a web beacon to set a cookie on your computer. In doing so, technical access data, information about the device and browser used, as well as data on the display of and interaction with advertisements may be processed. In addition, information on transactions carried out online and offline in the shop (event data such as appointment bookings, purchases, shopping basket value) as well as your hashed e-mail address are transmitted to Google Ads for the purpose of measuring success. We have no influence on the data collected, and we are not aware of the full extent of the data collection or the storage period. Your data is transferred to the USA and evaluated there. If you are logged in with your Google account, your data can be directly attributed to it. If you do not wish for this attribution to your Google profile, you must log out. It is possible that this data will be passed on to Google's contractual partners, to third parties and to authorities.

The service is only activated after you have given your consent. The legal basis is Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. This website does not display any third-party advertisements via Google AdSense.

You can prevent the installation of Google AdSense cookies in various ways: a) by means of a corresponding setting in your browser software; in particular, suppressing third-party cookies means that you will not receive advertisements from third-party providers; b) by deactivating interest-based advertising at Google via the link http://www.google.de/ads/preferences, whereby this setting will be deleted if you delete your cookies; c) by deactivating the interest-based advertisements of providers that are part of the self-regulatory campaign “About Ads” via the link http://www.aboutads.info/choices, whereby this setting will be deleted if you delete your cookies; d) by permanently deactivating this in your Firefox, Internet Explorer or Google Chrome browsers via the link http://www.google.com/settings/ads/plugin. We would point out that in this case you may not be able to use all functions of this offer to their full extent.

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Insofar as personal data is transmitted to Google LLC in the USA, we rely on the certification of Google LLC under the EU-U.S. Data Privacy Framework pursuant to Art. 45 GDPR. Further information: https://policies.google.com/technologies/ads?hl=de

You may withdraw your consent to the use of cookies and related technologies at any time.

Meta Pixel (Facebook and Instagram) and offline conversion measurement / matching of on-site events

We use the Meta Pixel (formerly “Facebook Pixel”, also for Instagram) of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Meta”) on our website. We use this to measure how users use our website after clicking on advertisements on Facebook and/or Instagram (e.g. page views, clicks, forms submitted, purchases/conversions). In addition, provided you have given your consent, we transmit certain on-site/offline events (e.g. transactions/conversions recorded in-store or via our point-of-sale system) to Meta in order to measure, attribute and optimise these in relation to online advertising campaigns (e.g. “Offline Conversions”, “Conversions API”, comparable Meta Business Tools).

Depending on the implementation, the following data in particular may be processed:

  • Online events from our website (e.g. page views, interactions, conversions) as well as technical information (including IP address, device/browser information, referrer URL, timestamp) and cookie/device identifiers.
  • Offline/on-site events (e.g. time and type of a transaction/conversion, branch/location, shopping basket/order information to the extent necessary).
  • Matching data/identifiers (e.g. e-mail address, telephone number or similar identifiers), hashed prior to transmission where applicable, so that Meta can carry out matching with user accounts. Hashed values generally continue to be regarded as personal data insofar as Meta is able to attribute them.

We generally receive aggregated evaluations (reports) from Meta, on the basis of which individual persons are typically not directly identifiable by us. However, Meta may be able to attribute the data to an existing Facebook/Instagram account.

Purposes of the processing:

  • Conversion measurement and campaign attribution (online and offline)
  • Optimisation of our advertising campaigns and audience formation (remarketing/custom audiences, where activated)
  • Preparation of statistical evaluations on advertising effectiveness.

Legal basis

The use of the Meta Pixel, as well as the transmission and matching of online and offline/on-site events with Meta, are only carried out following prior consent.

For the Meta Pixel on the website (in particular the setting/reading of cookies or comparable technologies and the associated tracking), the legal basis is

  • Art. 6(1)(a) GDPR (consent) and
  • Section 25(1) TDDDG for access to information on the terminal device or the storage of information on the terminal device.

For the transmission of offline/on-site data (e.g. purchases/conversions from the shop or point-of-sale system) to Meta, the legal basis is likewise Art. 6(1)(a) GDPR (consent),as the processing typically serves advertising/marketing purposes (measurement, attribution, optimisation, audience formation where applicable) and regularly requires active, informed and voluntary consent.

You can withdraw your consent at any time with effect for the future via our cookie settings, or send us an e-mail.

Recipients / joint controllership:The recipient of the data is Meta. For certain processing steps in connection with the Meta Pixel (in particular the collection and transmission of event data to Meta), joint controllership under Art. 26 GDPR between us and Meta may apply. Further information on this is provided by Meta in its relevant agreements and notices (e.g. the “Controller Addendum”).

Transfer to third countries:It cannot be ruled out that Meta also transfers data to states outside the EU/EEA (in particular the USA). Meta generally bases such transfers on appropriate safeguards, in particular the Standard Contractual Clauses (SCCs) of the EU Commission, as well as supplementary measures where applicable.

Storage period:In connection with the Meta Pixel, we generally do not permanently store any raw personal data ourselves, but instead use the evaluations provided by Meta. The storage period and further details of the processing are governed by Meta's specifications.

Further information / settings:Further information on the processing of data by Meta can be found in Meta's privacy policy:https://www.facebook.com/privacy/policy/. You can also adjust your advertising preference settings in your Facebook/Instagram account.

Microsoft Advertising

On our websites we integrate the service “Microsoft Advertising” of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.

In the European Union (EU) and the European Economic Area (EEA), the service is provided by Microsoft Ireland Operations, Ltd, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.

Description of the data processing and purpose

The service enables us to measure how successful our advertisements placed via Microsoft Advertising are.

For this purpose, we track how website visitors interact with the advertisements and their subsequent use of our websites. This involves tracking the conversion of an advertisement into an action by the website visitor (conversion tracking), with the aim of controlling and optimising our online marketing measures.

If an advertisement placed by us via “Microsoft Advertising” is displayed to you on other websites, or if you click on it, those other websites store a tracking cookie containing a pseudonym assigned to us on your terminal device, on the basis of the consent given by you there. If you subsequently visit our websites within the storage period of this cookie, this cookie is read out. In addition, when our websites are accessed, further pseudonymous cookies are stored on your terminal device in order to track your page views and interactions with our websites.

In particular, the following types of data are processed by the service:

  • Data on the website visit
  • IP address
  • Timestamp
  • Time zone
  • Data on the terminal device used to access the website
  • Hardware characteristics of the terminal device
  • Details of the operating system
  • Details of the web browser used
  • Language settings of the terminal device
  • Pseudonymous recognition feature of the terminal device
  • Data on the advertisement displayed
  • Data on the website on which the advertisement was displayed
  • Click by the website visitor on the advertisement
  • Data on the usage behaviour of our websites
  • websites visited
  • Duration and number of visits
  • Mouse movements
  • Click path
  • Successful completion of a defined target action by the website visitor (conversion)

Cookies and similar techniques, in particular JavaScript, may be used to store and read data on your device.

From the information collected, Microsoft creates statistics for us from which we can determine how many users responded to our advertisements and in what way.

The purpose of the data processing is to identify the effectiveness of online advertising campaigns and to manage our advertising strategy.

Legal basis for the data processing

The legal basis for the integration and use of the service is your consent, provided you have given it via our consent management platform.

The use of cookies and similar technologies is based on Section 25(1) TDDDG. The subsequent data processing is based on Art. 6(1) sentence 1(a) GDPR.

Your consent is voluntary and may be withdrawn at any time with effect for the future. To exercise your withdrawal, please use the “Cookie Settings” link at the bottom of the website to reopen the consent management platform and change your settings.

Recipients

In the course of the data processing, your data is transferred to the following recipients:

  • Microsoft Ireland Operations, Ltd, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland,
  • Microsoft Corporation, One Microsoft Way, Redmond WA 94043, USA.

Data processing in third countries

Your data is transferred to recipients in third countries. For data transfers to the USA, there is an adequacy decision by the EU Commission regarding companies certified under the EU-U.S. Data Privacy Framework. Microsoft Corporation is certified under the EU-U.S. Data Privacy Framework.

Storage period

Through the integration of the service on our websites, data is transferred to the recipients named above and stored there for a period of 13 months. The data processed by the service and made available to us is not stored beyond this in our own systems.

Hotjar

Our website uses the web analytics service Hotjar provided by Hotjar Ltd, Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe (“Hotjar”).

With the help of Hotjar's technology, we gain a better understanding of our users' experience (e.g. how much time users spend on which pages, which links they click, etc.). This helps us align our offering with our users' feedback. Hotjar uses cookies and other technologies to collect data about our users' behaviour and their devices, in particular the device's IP address (which is captured and stored only in anonymised form while you use our website), screen size, device type (unique device identifiers), information about the browser used, location (country only), and the preferred language for displaying our website. Hotjar stores this information on our behalf in a pseudonymised user profile.

When using this tool, we pay particular attention to protecting your personal data. As a result, we can only determine which buttons are clicked, the movement of the mouse, how far the page is scrolled, the device's screen size, device type and browser information, geographical location (country only), and the preferred language for displaying our website. Areas of the website where personal data belonging to you or third parties are displayed are automatically hidden by Hotjar and are therefore never traceable. The use of Hotjar and the associated processing of personal data takes place on the basis of your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

Hotjar generally stores customer data within the European Union. However, personal data may also be transferred to third countries outside the EU and the EEA. In such cases, additional safeguards must be taken to ensure the level of data protection required by the GDPR. To ensure this, we have agreed Standard Contractual Clauses (SCCs) with the provider pursuant to Art. 46(2)(c) GDPR. These oblige the recipient in the third country to process the data in accordance with the level of protection in the EU.

Recordings (session recordings) and heatmaps are automatically deleted no later than 12 months after the time of collection; the specific retention period depends on the Hotjar plan booked. De-identified user profiles without a user ID are deleted after three months of inactivity, and identified user profiles after twelve months of inactivity.

Hotjar gives every user the option of using a “Do Not Track” header to prevent the use of the Hotjar tool, so that no data about the visit to the relevant website is recorded. This is a setting supported by all common browsers in their current versions. To do this, your browser sends a request to Hotjar instructing it to disable tracking of the relevant user. If you use our websites with different browsers/computers, you must set up the “Do Not Track” header separately for each of these browsers/computers. You can prevent the use of Hotjar by going to the opt-out page https://www.hotjar.com/legal/compliance/opt-out and clicking “Disable Hotjar”.

Further information about Hotjar Ltd. and the Hotjar tool can be found at: https://www.hotjar.com. Hotjar Ltd.'s privacy policy can be found at: https://www.hotjar.com/privacy

TikTok Pixel

On our website we use the “TikTok Pixel” provided by TikTok Information Technologies UK Limited, Aviation House, 125 Kingsway Holborn, London, WC2B 6NH (“TikTok”). This is a code that we have implemented on our site.

If you have given your express consent, this code establishes a connection to TikTok's servers when you visit our website in order to track your behaviour on our website. In addition, TikTok Pixel also uses cookies through which information is stored on the device you use. With the help of the TikTok Pixel, TikTok is able, on the one hand, to identify you as a visitor to our online offering as part of a target group for the display of advertisements (so-called "TikTok Ads"). Accordingly, we use the TikTok Pixel to ensure that the TikTok Ads placed by us are shown only to those TikTok users who have also shown an interest in our online offering or who have certain characteristics (e.g. interests in particular topics or products, determined on the basis of the websites visited) that we transmit to TikTok (so-called “Custom Audiences”). With the help of the TikTok Pixel, we also aim to ensure that our TikTok Ads correspond to users' potential interests. With the help of the TikTok Pixel, we can further track the effectiveness of the TikTok advertisements for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a TikTok advertisement (so-called “conversion”).

Personal data such as the IP address and other information such as device ID, device type and operating system may also be transmitted to TikTok. TikTok uses email or other login or device information to identify the users of our website and to attribute their actions to a TikTok user account. TikTok uses this data to display targeted and personalised advertising to its users and to create interest-based user profiles. The data collected is anonymous and not visible to us, and can only be used by us for the purpose of measuring the effectiveness of advertisement placements.

The legal basis for the processing of your personal data for the purposes stated above is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

As personal data is transferred to third countries outside the EU, additional safeguards are required to ensure the level of data protection required by the GDPR. According to TikTok, data transfers to third countries take place under the European Commission's model contracts for the transfer of personal data to third countries (i.e. Standard Contractual Clauses) pursuant to Commission Decision 2004/915/EC or 2010/87/EU (as applicable), or under an alternative mechanism approved under EU law.

Further information on how TikTok processes personal data, including the legal basis on which TikTok relies and the options for exercising your rights against TikTok, can be found in TikTok's data policy at https://www.tiktok.com/legal/privacy-policy?lang=de-DE.

LinkedIn Insight Tag (LinkedIn Pixel)

On our website we use the LinkedIn Insight Tag (also known as the “LinkedIn Pixel”) provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”). With the help of the Insight Tag, we can determine how users use our website after clicking on a LinkedIn advertisement (so-called conversion measurement). We can also assign website visitors to target groups (remarketing) and thereby display our LinkedIn advertisements in a more targeted manner and statistically evaluate their success.

In particular, the following data may be processed when using the LinkedIn Insight Tag:

  • information on pages visited and interactions (e.g. page views, clicks, submitted forms/conversions)
  • technical information (including IP address, device/browser information, referrer URL, timestamp)
  • cookie/device identifiers or online identifiers

The information collected may enable LinkedIn to associate users with an existing LinkedIn account. We generally receive only aggregated analyses from LinkedIn, from which individual persons are typically not directly identifiable to us.

Legal basis: The LinkedIn Insight Tag (including the setting/reading of cookies or comparable technologies) is used only with your consent given via our consent management. The legal bases are Art. 6(1)(a) GDPR (consent) and Section 25(1) TDDDG for storing information on your device or accessing information already stored on your device. You may withdraw your consent at any time with effect for the future via our cookie settings.

The recipient of the data is LinkedIn. Depending on how the processing is structured, joint controllership pursuant to Art. 26 GDPR may apply to certain processing steps in connection with the Insight Tag. LinkedIn provides information on this in its contractual documents and privacy notices.

It cannot be ruled out that LinkedIn also transfers data to countries outside the EU/EEA (in particular the USA). Recipients in the USA may in particular be LinkedIn's affiliated companies, including LinkedIn Corporation. LinkedIn Corporation is certified under the EU-U.S. Data Privacy Framework. To the extent the transfer in question is covered by the scope of the certification, it takes place on the basis of the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework pursuant to Art. 45 GDPR. To the extent the EU-U.S. Data Privacy Framework is not applicable in an individual case, the transfer takes place on the basis of the European Commission's Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, together with additional technical and organisational measures where applicable.

In connection with the LinkedIn Insight Tag, we generally do not permanently store any raw personal data ourselves, but instead use the analyses provided by LinkedIn. The retention period at LinkedIn is determined by LinkedIn's own specifications.

Further information on data processing by LinkedIn: https://www.linkedin.com/legal/privacy-policy – advertising preferences: https://www.linkedin.com/psettings/advertising

OpenAI Advertisements (ChatGPT Ads) – Conversion Tracking

If we place advertisements via OpenAI's advertising platform (ChatGPT Ads), we use the conversion and audience tools provided by OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland (including the “OpenAI Pixel” and a server-side Conversions API). This allows us to determine whether and how users visit our website after coming into contact with one of our ChatGPT advertisements and what actions they take there (e.g. page views, purchases), in order to measure and optimise the effectiveness of our campaigns.

In this context, the following data may be processed: email address and telephone number (in hashed form), cookie and device/online identifiers, device and browser information, as well as event, transaction and purchase data.

OpenAI and we each process the data collected in connection with the use of these tools as independent controllers within the meaning of Art. 4 no. 7 GDPR; there is no joint controllership pursuant to Art. 26 GDPR. Further information on data processing by OpenAI is contained in the OpenAI Ad Tools Data Processing Addendum (https://openai.com/policies/ad-tools-dpa/) and in OpenAI's privacy policy (https://openai.com/policies/eu-privacy-policy/).

The legal basis is your consent pursuant to Art. 6(1)(a) GDPR; the use of cookies and similar technologies is based on Section 25(1) TDDDG. Your consent may be withdrawn at any time with effect for the future via our cookie settings.

As data may be transferred to OpenAI, Inc. in the USA, we have agreed Standard Contractual Clauses with OpenAI pursuant to Art. 46(2)(c) GDPR to ensure an adequate level of data protection.

7. External content, fonts, maps and media

Adobe Fonts

Adobe Fonts is used to display fonts. When retrieved, technical connection data, in particular the IP address and browser information, may be transmitted to Adobe. Integration takes place only after your consent, provided the fonts are not embedded locally. The legal basis is Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. The provider is Adobe Systems Software Ireland Limited, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland. To the extent data is transferred to the USA, we rely on Adobe's certification under the EU-U.S. Data Privacy Framework (Art. 45 GDPR). Further information: https://www.adobe.com/privacy.html

Google Fonts

On our websites we integrate the “Google Fonts” service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA.

In the European Union (EU) and the European Economic Area (EEA), the service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Description of the data processing and its purpose

“Google Fonts” enables us to use web fonts. To do this, the required Google Fonts are loaded by your web browser into your browser cache when our website is accessed. This is necessary so that your browser can also display a visually improved rendering of our text. If your browser does not support this function, a standard font from your computer is used for display.

As Google Fonts is provided by Google and is loaded from its servers when the page is accessed, the usage data technically required for accessing the page is also transmitted in the process.

The data processed includes, in particular:

  • Your IP address,
  • the date and time of the request,
  • the website accessed,
  • the referrer URL,
  • the browser used,
  • the operating system used.

Cookies and similar techniques, in particular JavaScript, may be used to store and read data on your device. Further details can be found above under “Data processing in connection with cookies and similar techniques”.

The purpose of the data processing and our legitimate interest lie in making our website visually more appealing to you.

Legal basis for the data processing

The legal basis for the integration and use of the service is your consent, provided you have given it via our consent management platform.

The use of cookies and similar technologies is based on Section 25(1) TDDDG. The subsequent data processing is based on Art. 6(1) sentence 1(a) GDPR.

Your consent is voluntary and may be withdrawn at any time with effect for the future. To exercise your withdrawal, please use the “Cookie Settings” link at the bottom of the website to reopen the consent management platform and change your settings.

Recipients

In the course of using the service, the data collected via our websites is transferred to the following recipients:

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland,
  • Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA.

Further information on the handling of personal data by the provider of the service can be found at https://policies.google.com/privacy?hl=de.

Data processing in third countries

Your data is transferred to recipients in third countries. For data transfers to the USA, there is an adequacy decision by the EU Commission regarding companies certified under the EU-U.S. Data Privacy Framework. Google LLC is certified under the EU-U.S. Data Privacy Framework.

Supplementary information on this, as well as further links, can be found above in the section “General information on data transfers to third countries”.

Storage period

Through the integration of the service on our websites, data is transferred to the recipients named above and processed there for as long as is necessary to achieve the stated purposes. The data processed by the service and made available to us is not stored beyond this in our own systems.

Google Maps

On our websites, we integrate the „Maps“ service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA.

In the European Union (EU) and the European Economic Area (EEA), the service is provided by Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland.

Description of the data processing and its purpose

The service enables us to provide you with interactive online maps directly on our websites.

As the service is provided by Google and is loaded from Google's servers when a page is accessed, the usage data technically required for accessing the page is also transmitted in the process:

  • IP address of the requesting entity (router or mobile device),
  • Date and time of the request,
  • Name of the requested file,
  • Website from which a file was requested (referrer URL),
  • Access status,
  • Web browser and operating system used,
  • Language used.

In addition, Google Maps itself uses the Google Fonts web fonts for display purposes and loads these from Google's servers when the page is accessed.

In addition, the service processes the following data:

  • Information about your location, which you may make available following authorisation via your browser or operating system,
  • Information from any search queries you have entered via the input fields of the interactive map.
  • Information relating to an existing Google account, if you are signed in to Google on your device.

Cookies and similar techniques, in particular JavaScript, may be used to store and read data on your device.

The purposes of the data processing are to make our website appealing to you, to make it easier for you to find our locations and premises, and to enable you to plan your route without difficulty.

Legal basis for the data processing

The legal basis for the integration and use of the service is your consent, insofar as you have given it via our consent management platform.

The use of cookies and similar technologies is based on Section 25(1) TDDDG. The subsequent data processing is based on Art. 6(1) sentence 1(a) GDPR.

Your consent is voluntary and may be withdrawn at any time with effect for the future. To exercise your withdrawal, please use the “Cookie settings” link at the bottom of the website to reopen the consent management platform and change your settings.

Recipients

In connection with the use of the service, the data collected via our websites is transmitted to the following recipients:

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland,
  • Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA.

Further information on the handling of personal data by the provider of the service can be found at https://policies.google.com/privacy?hl=de.

Data processing in third countries

Your data is transmitted to recipients in third countries. For data transfers to the USA, an adequacy decision of the EU Commission exists in respect of companies certified under the EU-U.S. Data Privacy Framework. Google LLC is certified under the EU-U.S. Data Privacy Framework.

Additional information on this, as well as further links, can be found above in the section “General information on data transfers to third countries”.

Storage period

Through the integration of the service on our websites, data is transmitted to the recipients named above and processed there for as long as is necessary to achieve the purposes stated. The data processed by the service and made available to us is not stored beyond this in our own systems.

Cloudinary

Cloudinary is used for the delivery and processing of images and other media. In this context, IP address, browser data and information relating to the requested media may be processed. The provider is Cloudinary Ltd., 3400 Central Expressway, Suite 110, Santa Clara, CA 95051, USA. The processing takes place as a processor arrangement on the basis of a data processing agreement (DPA) pursuant to Art. 28 GDPR. Insofar as the service is not technically necessary, it is only integrated after you have given your consent. In that case, the legal basis is Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR; for technically necessary media delivery, Art. 6(1)(f) GDPR applies. Insofar as data is transmitted to the USA, we rely on Cloudinary's certification under the EU-U.S. Data Privacy Framework (Art. 45 GDPR). Further information: https://cloudinary.com/privacy

Iconify Design

We use Iconify Design to display symbols and icons. When external icon files are retrieved, technical connection data, in particular your IP address, may be transmitted to the provider or the hosting provider of the respective resource. Insofar as the icons are integrated locally, no transmission to Iconify takes place when the icons are retrieved. Insofar as an external integration is required, it only takes place after you have given your consent. In that case, the legal basis is Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. Further information: https://iconify.design/

Sanity.io

We use Sanity.io for the management and delivery of website content. In this context, content, media and technical access data required for the display and operation of the website may be processed. The provider is Sanity.io, Inc., 548 Market St, Suite 95149, San Francisco, CA 94104, USA. The processing takes place as a processor arrangement on the basis of a data processing agreement (DPA) pursuant to Art. 28 GDPR. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the reliable provision of the website. Insofar as data is transmitted to the USA, this takes place on the basis of the Standard Contractual Clauses of the European Commission (Art. 46(2)(c) GDPR). Further information: https://www.sanity.io/legal/privacy

Sentry

We use the service Sentry (Sentry, 1501 Mariposa St #408, San Francisco, CA 94107, USA) to ensure and improve the technical stability of our service.

Sentry enables us to detect errors in our application that have led to a malfunction or a crash, to fix errors and to monitor the technical performance of the website.

Sentry uses cookies for this purpose, which, in the event of an error, transmit technical data such as browser data and the requesting IP address to Sentry in anonymised form. Sentry will use this information on our behalf to evaluate your use, to identify the source of the error and thereby give us the opportunity to fix the error and optimise our application. The legal basis is our legitimate interest pursuant to Art. 6(1) sentence 1(f) GDPR in the technical stability of our website. Sentry stores this data for as long as is necessary for the error evaluation, but for no longer than 90 days.

As a transfer of personal data by Sentry to affiliated companies and sub-processors in countries outside the EU and the EEA is possible, further protective mechanisms are required to ensure the level of data protection under the GDPR. For the USA, an adequacy decision of the EU Commission exists pursuant to Art. 45(1) GDPR in respect of companies certified under the EU-U.S. Data Privacy Framework. Sentry.io is certified under the EU-U.S. Data Privacy Framework and thereby commits to complying with appropriate data protection standards, which can be viewed at the following link: https://www.dataprivacyframework.gov/s/participant-search

For potential transfers to other third countries outside the EU and the EEA for which no adequacy decision of the EU Commission exists, we have additionally agreed Standard Contractual Clauses with the provider pursuant to Art. 46(2)(c) GDPR. These oblige the recipient of the data in the third country to process the data in accordance with the level of protection in Europe.

Please refer to Sentry's privacy notice for further information on the use of your data by the providers, as well as your related rights and setting options: https://sentry.io/privacy/#what-information-do-we-collect

Social media plugins

We do not use any social media plugins on our websites. If our websites contain icons of social media providers (e.g. Facebook, Instagram), these serve exclusively as passive links to the respective providers' profiles; no data is transmitted to these providers in the process.

8. Appointment booking and stores

Appointment booking via TIMIFY

We use TIMIFY for appointment booking. In particular, name, email address, telephone number, desired store, appointment time, selected service, reservation identifiers and messages may be processed via the appointment booking function. The purpose is the arrangement, management, confirmation and, where applicable, amendment or cancellation of consultation appointments in VIU stores. The processing takes place for the performance of pre-contractual measures or for the performance of a contract pursuant to Art. 6(1)(b) GDPR. The provider is TerminApp GmbH, Balanstraße 73, Gebäude Nr. 24, 3rd floor, 81541 Munich, Germany. The data is deleted after the appointment has taken place or after expiry of the agreed appointment period, insofar as no statutory retention obligations or open matters preclude this. Further information: https://www.timify.com/en/legal/privacy-policy/

Appointment-related cookies and storage

In connection with the management of appointments and orders, information may be stored in local storage and session storage. These entries contain only the information required for the respective appointment or order process.

Session storage entries are automatically deleted when the browser is closed. Local storage entries that serve exclusively for session control purposes are removed once the respective process has been completed.

9. Collection of personal data when contacting us

When you contact us, e.g. by email or live chat, we store the data you provide in order to answer your questions. We delete the data arising in this context once storage is no longer necessary for handling your enquiry, or we restrict the processing where statutory retention obligations apply. The data processing for the purpose of contacting us takes place pursuant to Art. 6(1) sentence 1(a) GDPR on the basis of your voluntarily given consent, and otherwise pursuant to Art. 6(1) sentence 1(b) GDPR, including where the data processing is necessary for the performance of a contract or for the performance of pre-contractual measures carried out at your request.

We use the customer service tool Intercom, provided by Intercom R&D Unlimited Company, 124 St Stephen's Green, Dublin 2, DC02 C628, Ireland. This tool enables us to offer you the service of getting in direct contact with our staff on our website by email or live chat.

If you use the live chat or contact us by email, the data communicated is processed by Intercom. In addition, when the live chat tool is used, certain information is automatically collected and processed by Intercom from your device via various types of technology, including cookies, "pixels" or "web beacons". This automatically collected information includes the IP address or another device address or ID, the web browser and/or device type, the web pages or websites visited immediately before or after using the service, the pages or other content that the user or visitor views or interacts with within the service, as well as the dates and times of the visit, access or use of the service.

The legal basis for the data processing is Art. 6(1)(a) GDPR. It takes place on the basis of your voluntarily given consent.

In the event that personal data is processed by Intercom outside the European Economic Area, Intercom has certified itself under the EU-U.S. Data Privacy Framework and thereby commits to complying with appropriate data protection standards, which can be viewed at the following link: https://www.dataprivacyframework.gov/s/participant-search

Further information on data protection at Intercom is available at https://www.intercom.com/legal/product-privacy-notice.

10. VIU Shops and online shop: account, online orders and in-store purchases, delivery and returns

Operation of the online shop by subsidiary companies

VIU Ventures AG provides the online shop as an online platform for online sales. Depending on the country, your contracting partner when placing orders via our online shop is the subsidiary company VIU AT GmbH, Neubaugasse 36, 1070 Vienna, Austria, or VIU Deutschland GmbH, Residenzstraße 27, 8033 Munich, Germany, which also organises the fulfilment of your order. For this purpose, your order data for online purchases made via the online shop on our website is transmitted to VIU AT GmbH or VIU Deutschland GmbH. The data processing carried out by VIU AT GmbH and VIU Deutschland GmbH takes place in accordance with the privacy policy of VIU Ventures AG.

Order and contract processing

For the processing of online orders and your in-store purchases, we process the data that you enter during the ordering process or that arises in connection with the order or the purchase in-store. This includes, in particular:

  • Name and contact details
  • Billing and delivery address
  • Email address and, where applicable, telephone number
  • Order, product, price, voucher, return and complaint data
  • Payment status and transaction information required for payment processing
  • Communication with customer service, as well as information on delivery and collection

The processing takes place for the performance of pre-contractual measures and for the performance of the purchase contract pursuant to Art. 6(1)(b) GDPR. The provision of the data required for the order, payment and delivery is necessary; without this data, we are generally unable to fulfil the order.

Customer account

You may voluntarily create a customer account. For this purpose, we process registration, login, profile, order and communication data in order to provide the account and to display previous orders and settings. The legal basis is Art. 6(1)(b) GDPR. The customer account can be deleted, provided that no statutory retention obligations or open matters preclude this. Registration using a Google or Apple account is possible; in this case, the profile data communicated by Google or Apple during the respective registration process (in particular name and email address) is processed. Further information: https://policies.google.com/privacy?hl=de and https://www.apple.com/legal/privacy/de-ww/ respectively

Payment service providers

For the processing of payments, we transmit the payment and transaction data required for this purpose to the respective selected payment service provider. Depending on the payment method, identity, device and security data may additionally be processed. The respective processing is additionally governed by the privacy policy of the payment service provider.

For payment processing, we use Adyen N.V., Simon Carmiggeltstraat 6, 1011 DJ Amsterdam, Netherlands. Adyen collects transaction-related data (including personal master data, communication data, IP address, payment data, order data) and transmits this to the financial service provider you have selected. We have entered into a data processing agreement (DPA) with Adyen. Further information: https://www.adyen.com/de_DE/privacy-policy. In addition, the following payment methods are offered: Visa (https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html), Mastercard (https://www.mastercard.de/de-de/datenschutz.html) and Twint by TWINT AG, Stauffacherstrasse 41, 8004 Zurich, Switzerland (https://shop.twint.ch/de/privacy-policy/). Address, payment and order data is retained for a period of ten years on the basis of commercial and tax law requirements; after two years, the processing is restricted to compliance with statutory obligations.

Shipping, collection and logistics

For the delivery or provision of ordered goods, we transmit the data required for this purpose to shipping, logistics and, where applicable, fulfilment service providers. In the case of collection at a store, the order and contact data required for identification and handover is transmitted to the respective store.

For shipping, we work with the transport service provider DPD Deutschland GmbH, Wailandtstraße 1, 63741 Aschaffenburg, Germany. We transmit your name and delivery address as well as – insofar as you have given your consent during the ordering process – your email address and/or telephone number, in order to arrange a delivery date. Consent may be withdrawn at any time with effect for the future. The legal basis is Art. 6(1)(b) GDPR (delivery) or Art. 6(1)(a) GDPR (delivery notification).

For shipping, we also work with the transport service provider DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany. We transmit your name and delivery address as well as – insofar as you have given your consent during the ordering process – your email address and/or telephone number, in order to arrange a delivery date. Consent may be withdrawn at any time with effect for the future. The legal basis is Art. 6(1)(b) GDPR (delivery) or Art. 6(1)(a) GDPR (delivery notification).

As transport service provider, we use the following provider: Post CH (Schweizerische PostAG, Switzerland, Wankdorfallee 4, 3030 Bern). We pass on your email address and/or telephone number to the provider prior to delivery of the goods, for the purpose of arranging a delivery date or for delivery notification, provided that you have given your express consent to this during the ordering process. Otherwise, for the purpose of delivery, we only pass on the recipient's name and the delivery address to the provider. This disclosure only takes place insofar as it is necessary for the delivery of the goods. In this case, prior arrangement of the delivery date with the provider or delivery notification is not possible. Consent may be withdrawn at any time with effect for the future, either towards the controller named above or towards the provider. In the case of a data transfer to the provider's location, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

For the manufacture of corrective lenses, we transmit the required order data (surname, order data, prescription values) to Optiswiss AG, Lyon-Strasse 26, 4053 Basel, Switzerland, and optovision Gesellschaft für moderne Brillenglastechnik mbH, Heinrich-Hertz-Straße 17, 63225 Langen, Germany. We have entered into data processing agreements (DPAs) with both manufacturers.

Automation of standard processes (Zapier)

To automate recurring standard processes in the online shop (e.g. sending order and invoice emails), we use the web service Zapier Inc., 548 Market St., San Francisco, CA 94104, USA. In this context, name, address, billing address, as well as order and invoice data, may be processed. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the efficient and low-error handling of standard processes. We have entered into a data processing agreement (DPA) with Zapier, which includes the Standard Contractual Clauses of the European Commission for the transfer of data to the USA. Further information: https://zapier.com/privacy.

Returns, warranty and customer service

We process data from returns, warranty and complaint processes in order to review and handle your enquiry, to fulfil statutory obligations, and to assert or defend against legal claims. The legal bases are Art. 6(1)(b), (c) and (f) GDPR.

11. Newsletter and promotional communications

If you sign up for our newsletter or other promotional email communications, we process your email address and, where applicable, other voluntary information you provide, in order to send you the requested information. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. Consent may be withdrawn at any time via the unsubscribe link in each message or via another contact channel specified by us.

To provide evidence of consent, the time of sign-up, IP address, time of confirmation and technical log data may be stored.

We use Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany) to send the newsletter and order confirmations. We use the double opt-in procedure. Unconfirmed sign-ups are automatically deleted after one month. Emails sent contain web beacons for evaluating opening and click behaviour; on the basis of this data, we create a user profile in order to tailor the newsletter to your interests. The data is stored for as long as you are subscribed to the newsletter; following unsubscription, it is used only in anonymised form for statistical purposes. We have concluded a data processing agreement (DPA) with Sendinblue GmbH. Further information: https://www.brevo.com/de/legal/privacypolicy/

Insofar as the newsletter includes open- or click-related measurement, this is only used subject to separate consent or on the basis of a legally reviewed, transparent configuration.

Advertising by post

On the basis of our legitimate interest in personalised direct marketing (Art. 6(1)(f) GDPR), we store your first and last name as well as your postal address and – where collected in the course of the contractual relationship – title, academic degree, year of birth and occupation, industry or job description, in order to send you offers and information about our products by post. You may object to the use of your data for this purpose at any time by contacting hello@shopviu.com.

12. Trustpilot reviews

We participate in the review process of Trustpilot A/S, Pilestræde 58, 5, 1112 Copenhagen, Denmark.

This allows you to review our products and, through the integration of Trustpilot reviews on our website, also to view other users' reviews of our products.

If you order a product through our online shop, we give you the opportunity to request that a review invitation be sent to you by Trustpilot. If you give your consent to the sending of the review invitation, for example by clicking a checkbox or a corresponding link, you will receive a review invitation containing a link to the relevant review page. In order to ensure that you have actually purchased the product to be reviewed, Trustpilot requests from us in this case the data required for this purpose, such as your name, your email address and your internal order number. This data is used solely to verify authenticity and to address you correctly. The legal basis for the processing of your data as part of the review process is your voluntarily given consent (Art. 6(1)(a) GDPR).

Furthermore, we have integrated Trustpilot reviews on our website via the Trustpilot widget, in order to show you reviews already given by other customers of the corresponding products. When the widget is called up, the web server automatically stores a so-called server log file, which contains, for example, your IP address, the date and time of the request, the amount of data transferred and the requesting provider (access data), and which documents the request. This access data is not evaluated and is automatically overwritten no later than seven days after the end of your visit to our website. The legal basis for this is Art. 6(1)(f) GDPR. Our legitimate interest follows from our interest in informing our customers about the quality of our products.

Trustpilot may also collect, via a cookie it sets, information indicating that you have visited our online offering. Trustpilot may store this information in a cookie in order to recognise which online offerings participating in the Trustpilot review process you have visited. Trustpilot may also store this information in a user profile and use it for advertising or market research purposes.

The legal basis for the above data processing via cookie is Art. 6(1)(a) GDPR. It is carried out on the basis of your voluntarily given consent.

You may withdraw your consent to the use of cookies and related technologies at any time.

Trustpilot's own, differing terms of use and privacy provisions apply to data processing at Trustpilot. Further information on the purposes and scope of data collection as well as the further processing and use of the data by Trustpilot can be found at https://de.legal.trustpilot.com/end-user-privacy-terms and https://de.legal.trustpilot.com/end-user-terms-and-conditions.

13. Job applications

On our websites, we integrate the HR and applicant management software „Personio“ from Personio GmbH, Rundfunkplatz 4, 80335 Munich, Germany.

Description of the data processing and its purpose

The service enables us to receive applications via forms on our websites and to store and manage the applicant data received.

If you send us your application data via the application form on our website, the data entered in the input form is transmitted to and stored by Personio.

As the service is provided by Personio and is loaded from its servers when the page is called up, the usage data technically required for calling up the page is also transmitted in the process:

  • IP address of the requesting device (router or mobile device),
  • Date and time of the request,
  • Name of the file requested,
  • Website from which a file was requested (referrer URL),
  • Access status,
  • Web browser and operating system used,
  • Language used.

In addition, the following data relating to your application is processed when you use the service:

  • Surname, first name,
  • Telephone number,
  • Place of residence / address,
  • Email address,
  • Salary expectations and start date
  • Curriculum vitae (CV),
  • References/certificates,
  • Cover letter,
  • Other uploaded attachments.

Cookies and similar techniques, in particular JavaScript, may be used to store and read data on your device.

The purposes of the data processing are to prepare for the possible conclusion of an employment relationship, to provide you with a simple way to apply, and to make the application process effective for us.

Legal basis for the data processing

Insofar as we use cookies and similar techniques in connection with the integration of the service, or insofar as data is stored on or read from your device by the service, this is carried out in accordance with Section 25(2) TDDDG.

Further data processing subsequently takes place for the purpose of initiating a contract or an employment relationship, at the request of the data subjects, on the basis of Art. 6(1) sentence 1(b) GDPR and Section 26(1) sentence 1 BDSG.

Recipients

As part of the data processing, your data is transmitted to the following recipients:

  • Personio GmbH, Rundfunkplatz 4, 80335 Munich, Germany.

Further information: https://www.personio.com/legal/privacy-policy/

Storage period

By integrating the service on our websites, data is transmitted to the recipients named above and stored there for a period of six months after the application process has concluded. Insofar as, in individual cases, data processed by the service and made available to us is stored beyond this in our own systems, this data is likewise retained for a maximum of six months after the application process has concluded, unless consent has been given for inclusion in a talent pool or further storage is required for the assertion of legal claims.

14. Use of artificial intelligence

Insofar as we use artificial intelligence applications as part of our website and shop offering, personal data may be processed. This may in particular be the case for customer service, product recommendations, personalisation, virtual try-on, fraud prevention, translations or internal workflows.

We do not currently use automated decision-making procedures, including profiling, within the meaning of Art. 22 GDPR. Should we use AI-supported applications in future, we will update this privacy policy accordingly.

We provide information on the respective use, purposes, data processed, providers, possible transfers to third countries, storage period and the protective measures applied in the respective sections of this privacy policy.

15. Recipients and processors

We only transmit personal data where this is necessary for the stated purposes, where consent has been given, or where there is a legal obligation to do so. Recipients may in particular include:

  • IT, hosting, CDN, content and security service providers
  • Providers of consent management, analytics, advertising and external content
  • Payment, shipping, logistics, fulfilment and returns service providers
  • Store and appointment booking service providers
  • Customer service, CRM, newsletter and communication service providers
  • Tax advisers, auditors, legal advisers and other professional advisers
  • Authorities, courts and other public bodies, where legally required

Processors with which we have concluded agreements pursuant to Art. 28 GDPR include, in particular: Google Ireland Limited (hosting, analytics, tag manager, maps, fonts), Cloudflare Germany GmbH (CDN), Usercentrics/Cybot A/S (consent management), Adyen N.V. (payment processing), DPD Deutschland GmbH and DHL Paket GmbH (shipping), Optiswiss AG and optovision GmbH (lens manufacturing), Sendinblue GmbH/Brevo (newsletter), TerminApp GmbH/TIMIFY (appointment booking), Cloudinary Ltd. (media delivery), Sanity.io Inc. (content management), Functional Software Inc./Sentry (error monitoring), Personio SE & Co. KG (job applications).

Intra-group data transfer

As part of intra-group cooperation, personal data may be transferred to companies affiliated with us within the VIU Group in Austria and Switzerland, insofar as this is necessary for the performance of shared business processes, the provision and administration of our systems, customer service, order processing or administrative purposes. The transfer to Switzerland is permissible on the basis of the European Commission's adequacy decision for Switzerland. This ensures a level of data protection comparable to that of the European Union. The data is processed only for the purposes stated in each case and to the extent necessary. Further recipients within the VIU Group receive personal data only where an appropriate legal basis under data protection law exists for this.

16. Data transfer to third countries

For certain services, processing may take place outside the European Union or the European Economic Area. A transfer only takes place where the requirements of Art. 44 et seq. GDPR are met. Depending on the recipient, this may in particular involve an adequacy decision of the European Commission (e.g. for Switzerland), certification under the EU-U.S. Data Privacy Framework, Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, as well as supplementary technical and organisational measures.

The requirements set out in this section and in the respective section for each service apply to every service used. Where necessary, we additionally provide information on suitable safeguards and specific recipients.

Data transfers to third countries only take place insofar as this is necessary for the respective services and an appropriate level of protection is ensured. For transfers to the USA, we rely on the Standard Contractual Clauses of the European Commission (Art. 46(2)(c) GDPR) and, where applicable, on the recipient's certification under the EU-U.S. Data Privacy Framework.

17. Storage period and deletion

We store personal data only for as long as this is necessary for the respective purposes. We then delete the data, unless statutory retention obligations, legitimate interests in preserving evidence, or outstanding legal claims justify further processing.

Statutory retention periods may apply to documents relevant under commercial and tax law, in particular under the German Commercial Code (Handelsgesetzbuch) and the Fiscal Code (Abgabenordnung). The period generally begins at the end of the calendar year in which the document was created or the matter was concluded.

Address, payment and order data: ten years due to retention obligations under commercial and tax law; after two years, processing is restricted to the fulfilment of statutory obligations. Customer account: until deletion by the data subject, provided no statutory retention obligations or outstanding matters preclude this. Newsletter data: until unsubscription, thereafter only in anonymised form. Appointment booking data: until the appointment has taken place, and beyond that only insofar as required for its handling or for statutory obligations. Technical log data: only for as long as required for secure operation, error analysis and defence against attacks. Evidence of consent: twelve months, unless longer retention is required as evidence. Analytics and advertising data: in accordance with the respective provider and account settings, at the latest as soon as it is no longer required for the respective purposes.

18. Your rights

Below you will find information on the data subject rights that applicable data protection law grants you vis-à-vis the controller with regard to the processing of your personal data:

The right, pursuant to Art. 15 GDPR, to request information about the personal data concerning you that we process. In particular, you may request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the envisaged storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected from you, and the existence of automated decision-making, including profiling, and, where applicable, meaningful information about the details thereof.

The right, pursuant to Art. 16 GDPR, to request the immediate rectification of inaccurate personal data or the completion of personal data stored by us.

The right, pursuant to Art. 17 GDPR, to request the erasure of your personal data stored by us, provided that the processing is not necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims.

The right, pursuant to Art. 18 GDPR, to request the restriction of the processing of your personal data, provided that you contest the accuracy of the data, the processing is unlawful but you oppose its erasure, we no longer need the data but you require it for the establishment, exercise or defence of legal claims, or you have objected to the processing pursuant to Art. 21 GDPR.

The right, pursuant to Art. 20 GDPR, to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transmitted to another controller.

The right, pursuant to Art. 77 GDPR, to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority of the federal state (Bundesland) of our registered office stated above, or, where applicable, that of your habitual residence or place of work.

The right to withdraw consent given, pursuant to Art. 7(3) GDPR: You have the right to withdraw consent once given to the processing of data at any time, with effect for the future. In the event of withdrawal, we will delete the data concerned without delay, unless further processing can be based on a legal basis permitting processing without consent. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent prior to its withdrawal.

Right to object

Insofar as your personal data is processed by us on the basis of legitimate interests pursuant to Art. 6(1) sentence 1(f) GDPR, you have the right, pursuant to Art. 21 GDPR, to object to the processing of your personal data, provided that this is done for reasons arising from your particular situation. Insofar as the objection is directed against the processing of personal data for the purposes of direct marketing, you have a general right to object without the need to state a particular situation.

If you wish to exercise your right of withdrawal or objection, please contact the details given above under Controller.

19. Updates to this privacy policy

The current version of this privacy policy is dated August 2026. We may amend this privacy policy if the data processing, the legal situation or the services used change. The version published on this website at any given time shall apply.