FREE SHIPPING: Germany / 100 € rest of Europe / 150 € USA

FREE SHIPPING: Germany / orders above 100 € rest of Europe / orders above 150 € USA

Your cart

Your cart is empty

Privacy policy

Data Controller:

Natalie's Cosmetics GmbH 
Hildegardstraße 9 
80539 Munich 
Germany 
support@natalies-cosmetics.com

We appreciate your interest in our online shop. The protection of your privacy is of great importance to us. Below, we provide detailed information about how we handle your data.

1. Access Data and Hosting

You can visit our websites without providing any personal information. Every time a webpage is accessed, the web server automatically stores a server log file, which includes information such as the name of the requested file, your IP address, date and time of access, amount of data transferred, and the requesting provider (access data). These access data are solely used to ensure the proper functioning of the website and to improve our services. This is done to safeguard our legitimate interests in providing a correct representation of our services within the scope of a balancing of interests, as per Art. 6 para. 1 s. 1 lit. f GDPR. All access data are deleted no later than seven days after your visit to the website.

Hosting

Our website is hosted based on a data processing agreement (Art. 28 GDPR) with Shopify International Limited, 2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. While the processing of personal data is not the primary responsibility of the hosting provider, it cannot be ruled out that the hosting provider may still have access to personal data processed via the website. Shopify processes data exclusively on servers located in the EU and Canada, for which the EU Commission has determined an adequate level of data protection, making data transfers under Art. 45 para. 3 GDPR lawful.

2. Data Processing for Contractual Fulfillment, Contact, and Opening a Customer Account

We collect personal data when you voluntarily provide it to us during the ordering process or when contacting us (e.g., via a contact form or email). Mandatory fields are marked as such, as we require this data for the purpose of contract fulfillment and processing your inquiries. Without providing this information, you cannot submit your order or contact us. The data collected is visible in the respective input forms. We use the data you provide for contract fulfillment and processing your inquiries, in accordance with Art. 6 para. 1 s. 1 lit. b GDPR.

If you have given your consent pursuant to Art. 6 para. 1 s. 1 lit. a GDPR by choosing to open a customer account, we use your data for the purpose of creating a customer account. Further information regarding the processing of your data, especially with regard to the disclosure to our service providers for order processing, payment, and shipping, can be found in the following sections of this privacy policy. After the complete fulfillment of the contract or the deletion of your customer account, your data will be restricted for further processing and deleted after the expiration of the legal retention periods under Art. 6 para. 1 s. 1 lit. c GDPR, unless you have expressly consented to further use of your data pursuant to Art. 6 para. 1 s. 1 lit. a GDPR, or unless we reserve the right to use your data beyond what is legally permitted, as detailed in this statement. The deletion of your customer account is possible at any time and can be initiated either by sending a message to the contact information described in this privacy policy or through a designated function in your customer account.

3. Data Processing for Shipping

For contract fulfillment pursuant to Art. 6 para. 1 s. 1 lit. b GDPR, we share your data with the shipping service provider responsible for delivering the ordered goods when necessary for delivery. Data is also shared with shipping service providers for the purpose of delivery notifications. If you have given us explicit consent for this during or after your order, we share your email address and phone number with the selected shipping service provider. This is done to facilitate delivery notifications and coordination.

You can revoke this consent at any time by sending a message to the contact information described in this privacy policy or directly to the shipping service provider at the contact address provided below. After revocation, we will delete the data you provided for this purpose, unless you have explicitly consented to further use of your data, or unless we reserve the right to use your data beyond what is legally permitted, as detailed in this statement.

Shipping Service Providers:

Quivo GmbH 
Wiedner Gürtel 9-13 
1100 Vienna 
Austria

United Parcel Service Deutschland S.à r.l. & Co. OHG 
Görlitzer Straße 1 
41460 Neuss 
Germany

DHL Paket GmbH 
Sträßchensweg 10
 53113 Bonn
Germany

FedEx Express Deutschland GmbH 
Langer Kornweg 34k 
65451 Kelsterbach

Use of Special Service Providers for Order Processing and Fulfillment. Order processing can also be carried out by a fulfillment provider. Your name, address, all or parts of your ordered items, and potentially other personal data are shared with the fulfillment provider solely for the purpose of processing your online order, pursuant to Art. 6 para. 1 s.1 lit. b GDPR. Your data is shared to the extent necessary for order processing, i.e., contract fulfillment. The legal basis for data processing is Art. 6 para. 1 s.1 lit. b GDPR (contract fulfillment) and our legitimate interest in an efficient and effective order processing, as per Art. 6 para. 1 s.1 lit. f GDPR.

4. Data Processing for Payment Transactions

In the execution of payments in our online shop, we collaborate with the following partners: technical service providers, credit institutions, and payment service providers.

4.1 Data Processing for Transaction Handling

Depending on the selected payment method, we share the data necessary for processing the payment transaction with our technical service providers, who work on our behalf under a data processing agreement, or with the designated credit institutions or the chosen payment service provider, as required for payment processing. This is done to fulfill the contract, as per Art. 6 para. 1 s. 1 lit. b GDPR. In some cases, payment service providers collect the data required for payment processing themselves, either on their own website or through a technical integration during the ordering process. In such cases, the data protection policy of the respective payment service provider applies. If you have questions regarding our payment processing partners and the basis of our cooperation with them, please contact the contact information provided in this privacy policy.

4.2 Data Processing for Fraud Prevention and Optimization of Payment Processes

We may provide our service providers with additional data to be used in conjunction with the data required for payment processing. This data is processed as our data processors for the purpose of fraud prevention and optimizing our payment processes (e.g., invoicing, handling disputed payments, assisting with accounting). This is done to safeguard our predominant legitimate interests in fraud prevention and efficient payment management, as per Art. 6 para. 1 s. 1 lit. f GDPR.

4.3 Identity and Credit Check When Selecting Klarna Payment Services

Klarna Pay now (direct debit), Klarna Pay later (purchase on account), Klarna Slice it (installment purchase). When you choose the payment services of Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter Klarna), we request your consent, as per Art. 6 para. 1 s. 1 lit. a GDPR, to transmit the data necessary for processing the payment and for identity and credit checks to Klarna. In Germany, the Wirtschaftsauskunfteien (credit bureaus) mentioned in Klarna's privacy policy [https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/privacy] can be used for identity and credit checks. Klarna uses information about the statistical probability of a payment default for making an informed decision about the initiation, execution, or termination of the contract relationship. You can revoke your consent at any time by sending a message to the contact information provided in this privacy policy. This may result in us no longer offering certain payment options. You can also revoke your consent to the use of personal data for this purpose directly with Klarna.

5. Email Advertising

5.1 Existing Customer Email Advertising

When you make a purchase with us, we use your contact information to send you relevant information about our products via email ("existing customer advertising"). This may include information about new products, promotions, offers, as well as feedback and other surveys. The legal basis for this data processing is Art. 6 para. 1 lit. f GDPR in conjunction with § 7 para. 3 UWG, which allows data processing for the purpose of legitimate interests, specifically regarding the storage and further use of data for advertising purposes. To provide you with only relevant offers in the existing customer newsletter, customer segmentation is performed using the data you provided during your order. The legal basis for this processing is our legitimate interest, as mentioned above, according to Art. 6 para. 1 lit. f GDPR. You can object to the use of your data for promotional purposes at any time by using the unsubscribe link in the emails or by contacting us through the contact details provided in this privacy policy (e.g., via email or mail). This will not result in any charges other than standard communication costs.

5.2 Email Newsletter with Registration

When you subscribe to our newsletter, we use the data required for this purpose, or that you provide separately, to regularly send you our email newsletter, based on your consent, as per Art. 6 para. 1 s. 1 lit. a GDPR. You can unsubscribe from the newsletter at any time, either by sending a message to the contact information provided below or by using the designated link in the newsletter. After unsubscribing, we will remove your email address from the recipient list unless you have explicitly consented to further data use under Art. 6 para. 1 s. 1 lit. a GDPR, or unless we reserve the right for data usage beyond what is legally permitted, as detailed in this statement.

5.3 Newsletter Delivery

The newsletter may also be sent by our service providers as part of processing on our behalf. For questions regarding our service providers and the basis of our cooperation with them, please contact the contact information provided in this privacy policy. Our service provider, Klaviyo Inc. (https://www.klaviyo.com/legal), may determine and analyze the reach of our newsletters. We can also determine whether a newsletter message was opened and which links were possibly clicked. This allows us to see which links were clicked most frequently and were of particular interest to you and others. Additionally, we can identify whether specific predefined actions, such as a purchase, were taken after opening/clicking (conversion rate). Klaviyo also enables us to categorize newsletter recipients into different categories and form clusters. This way, we can better tailor the newsletter to the respective target groups. Klaviyo is based in the USA (125 Summer Street, Boston, MA 02110 / USA) and processes data from you on our behalf. This may also happen in the USA. There is currently no adequacy decision of the European Commission for the USA. Our cooperation is based on the standardized data protection clauses of the European Commission, which are integrated into the Data Processing Agreement we have concluded with Klaviyo and can be found here. For further information about Klaviyo's data processing, please refer to Klaviyo's privacy policy.

5.4 Existing Customer Advertising via Mail

If you have entered into a contract with us, you will be considered an existing customer. In this case, we process your postal contact information to send you information about new products and services via mail. The legal basis for this is Art. 6 para. 1 lit. f GDPR in conjunction with § 7 para. 3 UWG. You can object to the use of your data for advertising purposes at any time by contacting us at the contact details provided above (e.g., via email or mail). This will not result in any charges other than standard communication costs.

6. Cookies and Other Technologies

6.1 General Information

To make your visit to our website attractive and enable the use of certain features, we use technologies, including so-called cookies, on various pages. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted after the browser session ends, meaning when you close your browser (session cookies). Other cookies remain on your device, allowing us to recognize your browser on your next visit (persistent cookies).

We use such technologies that are essential for the use of specific features on our website, such as the shopping cart function. These technologies collect and process your IP address, visit time, device and browser information, as well as information regarding your use of our website (e.g., shopping cart contents). This processing is carried out as part of a balancing of legitimate interests in optimizing our offerings, pursuant to Art. 6, Paragraph 1, Sentence 1, lit. f of the GDPR.

Additionally, we use technologies to fulfill our legal obligations, such as proving consents to process your personal data, as well as for web analysis and online marketing. Further information, including the legal basis for data processing, can be found in the subsequent sections of this privacy policy.

You can find the cookie settings for your browser using the following links: Microsoft Edge™ [https://support.microsoft.com/de-de/help/4027947/microsoft-edge-delete-cookies] / Safari™ [https://support.apple.com/de-de/guide/safari/sfri11471/12.0/mac/10.14] / Chrome™ [https://support.google.com/chrome/answer/95647?hl=de&hlrm=en] / Firefox™ [https://support.mozilla.org/de/products/firefox/protect-your-privacy/cookies] / Opera™ [https://help.opera.com/de/latest/web-preferences/#cookies].

If you have provided consent to the use of these technologies in accordance with Art. 6, Paragraph 1, Sentence 1, lit. a of the GDPR, you can revoke your consent at any time by sending a message to the contact provided in the privacy policy. Alternatively, you can use the following link: [https://natalies-cosmetics.com/policies/privacy-policy]. Please note that rejecting cookies may restrict the functionality of our website.

6.2 GDPR Legal Cookie Consent Management

On our website, we use the Avada EU GDPR Cookie Consent App from AVADA Commerce, Pte. Ltd. to inform you about the cookies and other technologies we use on our website and to obtain, manage, and document your consent, if necessary, for processing your personal data with these technologies. This is required under Art. 6, Paragraph 1, Sentence 1, lit. c of the GDPR to fulfill our legal obligation under Art. 7, Paragraph 1 of the GDPR to be able to prove your consent to the processing of your personal data. GDPR Legal Cookie is provided by AVADA Commerce, Pte. Ltd., 1 Sophia Rd, Peace Centre, Singapore, 228149, who processes your data on our behalf.

After providing your cookie declaration on our website, the GDPR Legal Cookie webserver stores your anonymized IP address, the date and time of your declaration, browser information, the URL from which the declaration was sent, information about your consent behavior, and an anonymous random key. In addition, a cookie is used that contains information about your consent behavior and the key. Your data is deleted after twelve months unless you have expressly consented to further use of your data under Art. 6, Paragraph 1, Sentence 1, lit. a of the GDPR, or if we reserve the right for further data usage that is legally permitted, which we will inform you about in this declaration.

7. Use of Cookies and Other Technologies for Web Analysis and Advertising

If you have provided consent for this under Art. 6, Paragraph 1, Sentence 1, lit. a of the GDPR, we use the following cookies and other technologies from third-party providers on our website. The data collected in connection with these technologies will be deleted once the respective technology is no longer in use. You can withdraw your consent at any time with future effect. For more information on how to withdraw your consent, please refer to the "Cookies and Other Technologies" section. Further information, including the legal basis for data processing, can be found with each technology provider. If you have questions about the providers and the basis for our collaboration with them, please contact the contact information provided in this privacy policy.

7.1 Use of Google Services

We use the following technologies from Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). The information automatically collected through Google technologies about your use of our website is usually transmitted to a server of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and stored there. There is no adequacy decision by the European Commission for the USA. Our cooperation is based on the standard data protection clauses of the European Commission. If your IP address is collected through the Google technologies, it will be shortened before being stored on Google's servers by activating IP anonymization. Only in exceptional cases is the full IP address transmitted to a Google server and shortened there. Unless otherwise stated for each technology, data processing is based on an agreement between the joint controllers according to Art. 26 of the GDPR. For further information about data processing by Google, please refer to Google's privacy policy [https://policies.google.com/privacy?hl=de].

Google Analytics

We use Google Analytics 4 on our website, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter referred to as "Google"). In this context, pseudonymous user profiles are created, and cookies are used. Information generated by the cookie about the use of our website, such as the IP address of the accessing device, the time of access, referrer URL, and details about the browser and operating system used, is typically transmitted to Google servers in the United States and processed there.

The use of Google Analytics is carried out with your consent (Art. 6 para. 1 sentence 1 lit. a GDPR in conjunction with § 25 para. 1 TDDSG) for the purpose of analyzing and optimizing our online offerings, as well as for the economic operation of this website. Therefore, Google processes this information on our behalf to evaluate website usage, compile reports on website activities, and provide other services related to website and internet usage for market research and the tailored design of these web pages towards us.

We have concluded a data processing agreement with Google for the use of Google Analytics. Through this agreement, Google assures that it processes data in accordance with the General Data Protection Regulation and ensures the protection of the rights of data subjects. The IP address processed by Google Analytics is automatically truncated. The last three digits of your IP address are replaced with "0," preventing any direct association. If required by law, or if third parties process this data on behalf of Google, the collected user data via cookies is automatically deleted after 2 months.

Please note: Information generated by cookies about the use of our website, such as the IP address of the accessing device, the time of access, referrer URL, and details about the browser and operating system used, is transmitted to Google servers in the United States, which are considered "inadequate" in terms of data protection according to European Commission standards. Google relies on the transmission of Standard Contractual Clauses approved by the European Commission as a guarantee of data protection in line with European Union standards. You can obtain a copy of the Standard Contractual Clauses here. You can withdraw or adjust your consent at any time for future purposes. For more information on data protection related to Google Analytics, refer to the Google Analytics help section. Information about Google's data usage can be found in their privacy policy.

Google Signals enables cross-device tracking through the extension function of Google Analytics for web analysis. If your internet-capable devices are linked to your Google account and you have enabled the "personalized advertising" setting in your Google account, Google can generate reports on your usage behavior, especially regarding cross-device user numbers, even when you switch devices. No personal data processing takes place by us in this regard; we only receive statistics generated based on Google Signals.

For web analysis and advertising purposes, Google Analytics uses the DoubleClick cookie, allowing for recognition of your browser when visiting other websites. Google uses this information to compile reports on website activities and provide additional services related to website use.

Google Ads

For advertising purposes in Google search results and on third-party websites, we set a Google Remarketing cookie when you visit our website. It enables interest-based advertising automatically through the collection and processing of data, such as the IP address, time of visit, device and browser information, and information about your use of our website. Additional data processing occurs only if you have activated the "personalized advertising" setting in your Google account. In this case, when you visit our website and are logged into your Google account, Google uses your data in conjunction with Google Analytics data to create and define target audience lists for cross-device remarketing.

To measure web analysis and event management, we track your subsequent usage behavior if you arrive at our website via a Google Ads advertisement using Google Ads Conversion Tracking. Cookies may be employed, and data, such as your IP address, time of visit, device and browser information, and information about your use of our website, are collected based on events defined by us, such as visiting a webpage or signing up for a newsletter. Using pseudonyms, user profiles are created from this data.

Google reCAPTCHA

For the purpose of protecting our web forms from abuse and spam by automated software (so-called bots), Google collects reCAPTCHA data (IP address, visit timestamp, browser information, and information about your use of our website). This data is analyzed through the use of JavaScript and cookies. Additionally, other cookies stored in your browser by Google services are evaluated. No extraction or storage of personal data from the input fields of the respective form occurs.

7.2 Use of Meta Services

Use of Meta Pixel

We use the Meta Pixel as part of the technologies provided by Meta Platforms Ireland Ltd [https://about.meta.com/de/metaverse/], 4 Grand Canal Square, Dublin 2, Ireland ("Meta"). The Meta Pixel automatically collects and stores data (IP address, visit timestamp, device and browser information, as well as information about your use of our website) based on predefined events we specify, such as visiting a webpage or subscribing to a newsletter. Within the context of the so-called extended data matching, information hashed for matching purposes is also collected and stored, which can identify individuals (e.g., names, email addresses, and phone numbers). During your visit to our website, the Meta Pixel automatically sets a cookie that enables your browser to be recognized pseudonymously by a cookie ID when visiting other websites. Meta will combine this information with additional data from your Meta account to compile reports on website activities and provide other services related to website use, especially personalized and group-based advertising.

The information automatically collected by Meta technologies regarding your use of our website is typically transferred to a server of Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA, and stored there. The European Commission has not issued an adequacy decision for the USA. If data transmission to the USA falls under our responsibility, our cooperation is based on Standard Contractual Clauses of the European Commission. For more information about data processing by Facebook, please refer to Facebook's privacy policy [https://www.facebook.com/privacy/policy/].

Meta Analytics

Under Meta Analytics, statistics on visitor activities on our website are generated from data collected through the Meta Pixel. Data processing is based on a data processing agreement with Meta. The analysis is aimed at optimizing the presentation and marketing of our website.

Meta Platform Ads

We advertise this website on Meta and other platforms through Meta-Ads. We determine the parameters of each advertising campaign. For the exact execution, especially the decision on ad placement for individual users, Meta is responsible. Unless otherwise specified for individual technologies, data processing is based on an agreement between joint controllers according to Art. 26 GDPR. Joint responsibility is limited to the collection of data and its transmission to Meta. Subsequent data processing by Meta is not covered by this.

Based on statistics on visitor activities on our website created through the Meta Pixel, we conduct group-based advertising on Meta under Meta Custom Audience by defining the characteristics of the target audience and showing Meta-Ads only to Meta users who have shown an interest in our online offerings or who have specific characteristics (e.g., interests in certain topics or products determined from visited websites) that we convey to Meta (so-called "Meta Custom Audiences"). This allows us to ensure that our Meta-Ads correspond to users' potential interests and are not intrusive. Furthermore, we can evaluate the effectiveness of Meta ads for statistical and market research purposes by tracking whether a user was redirected to our website after clicking on a Meta ad (so-called "conversion").

The data collected is anonymous to us and does not provide us with any information about the identity of users. However, Meta stores and processes the data, enabling a connection to the respective user profile, and Meta can use the data for its own advertising purposes in accordance with the Meta Platform Data Use Policy (https://www.facebook.com/about/privacy/). The data can enable Meta and its partners to display ads on and outside the Meta platform.

Based on the pseudonymous cookie ID set by the Meta Pixel and the data collected about your usage behavior on our website, we conduct personalized advertising via Meta Pixel Remarketing.

The data processing associated with the use of the Meta Pixel occurs only with your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with future effect.

7.3 Other Providers of Web Analysis and Online Marketing Services

Use of TWIPLA for Web Analysis

TWIPLA [https://www.twipla.com/] is a straightforward website analysis service that measures traffic on our website and collects general information about our website visitors. We create statistics to enhance the experience of our website visitors. We do not use cookies for this purpose. As website operators using TWIPLA for audience measurement, depending on the level of data protection enabled, we may process information about the device you use, its characteristics, technical features of the website visit, the number of page visits, and statistically relevant behaviors of our website visitors. The technology does not use the collected data to identify individual visitors or match the data with additional information about a single user. Depending on your location when accessing our website, TWIPLA may not collect information about your device based on our technical settings.

Use of Pinterest Tag for Web Analysis and Advertising

For web analysis and advertising purposes on Pinterest and on third-party websites, technologies of Pinterest Europe Ltd [https://www.pinterest.de/], Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland ("Pinterest") are automatically used to enable interest-based advertising through the collection and processing of data (IP address, visit timestamp, device and browser information, and information about your use of our website based on predefined events such as visiting a webpage or subscribing to a newsletter) and through a pseudonymous cookie ID. Pseudonymous usage profiles are created from the collected data. Pinterest will combine this information with additional data from your Pinterest account to compile reports on website activities and provide other services related to website use. We have no control over data processing by Pinterest and only receive statistics created based on the Pinterest Tag. Thus, we measure your subsequent usage behavior for website analysis and event tracking when you arrive at our website via a Pinterest ad. The information automatically collected by Pinterest is usually transferred to a server of Pinterest, Inc., 505 Brannan St., San Francisco, CA 94107, USA, and stored there. The European Commission has not issued an adequacy decision for the USA. Our cooperation is based on Standard Contractual Clauses of the European Commission. Data processing is conducted on the basis of an agreement between joint controllers according to Art. 26 GDPR.

JudgeMe

Natalie’s Cosmetics GmbH may contact you via email to invite you to evaluate services and/or products you have received from us in order to collect your feedback and improve our services and products (the "Purpose"). We use an external company, Judge.Me Ltd, to collect your feedback, which means we share your name, email address, and reference number with Judge.Me Ltd for this Purpose. If you'd like to learn more about how Judge.Me Ltd processes your data, you can find their privacy policy here: https://judge.me/privacy. Natalie’s Cosmetics GmbH may also use such reviews in other promotional materials and media for our advertising and promotional purposes.

8. Social Media

8.1 Social Plugins by Meta, Instagram, Pinterest, WhatsApp

On our website, we use social network social buttons. These are simply embedded as HTML links on the page, so no connection is made to the servers of the respective provider when you visit our website. Clicking on one of the buttons will open the webpage of the respective social network in a new window of your browser. There, you can, for example, activate the like or share button.

8.2 Our Online Presence on Meta, Instagram, YouTube, Pinterest, LinkedIn, TikTok

If you have provided your consent pursuant to Article 6(1) sentence 1 lit. a GDPR to the respective social media operator, your data will be automatically collected and stored for market research and advertising purposes when you visit our online presence on the social media platforms mentioned above. Pseudonymous usage profiles will be created from this data. These profiles can be used, for example, to display advertisements within and outside the platforms that presumably correspond to your interests. Cookies are typically used for this purpose. For detailed information on the processing and use of data by the respective social media operator, as well as contact options and your related rights and privacy protection settings, please refer to the privacy policies linked below. If you need further assistance, you can contact us.

Meta [https://www.facebook.com/about/privacy/] is provided by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Meta"). Information automatically collected by Meta about your usage of our online presence on Meta is usually transferred to a server of Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA, and stored there. The European Commission has not issued an adequacy decision for the USA. Our cooperation is based on Standard Contractual Clauses of the European Commission. Data processing during the visit to a Meta fan page is based on an agreement between joint controllers pursuant to Art. 26 GDPR. Additional information (Insights Data Information) can be found here [https://www.facebook.com/legal/terms/information_about_page_insights_data].

Instagram [https://help.instagram.com/519522125107875] is provided by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Meta"). Information automatically collected by Meta about your usage of our online presence on Instagram is usually transferred to a server of Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA, and stored there. The European Commission has not issued an adequacy decision for the USA. Our cooperation is based on Standard Contractual Clauses of the European Commission. Data processing during the visit to an Instagram fan page is based on an agreement between joint controllers pursuant to Art. 26 GDPR. Additional information (Insights Data Information) can be found here [https://www.facebook.com/legal/terms/information_about_page_insights_data].

YouTube [https://policies.google.com/privacy?hl=de] is provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Information automatically collected by Google about your usage of our online presence on YouTube is usually transferred to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA, and stored there. The European Commission has not issued an adequacy decision for the USA. Our cooperation is based on the Standard Contractual Clauses of the European Commission.

Pinterest [https://about.pinterest.com/de/privacy-policy] is provided by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland ("Pinterest"). Information automatically collected by Pinterest about your usage of our online presence on Pinterest is usually transferred to a server of Pinterest, Inc., 505 Brannan St., San Francisco, CA 94107, USA, and stored there. The European Commission has not issued an adequacy decision for the USA. Our cooperation is based on the Standard Contractual Clauses of the European Commission.

LinkedIn [https://www.linkedin.com/legal/privacy-policy] is provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland ("LinkedIn"). Information automatically collected by LinkedIn about your usage of our online presence on LinkedIn is usually transferred to a server of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA, and stored there. The European Commission has not issued an adequacy decision for the USA. Our cooperation is based on the Standard Contractual Clauses of the European Commission.

TikTok, Mailing Address: TikTok Inc., Attn: TikTok Legal Department 10100 Venice Blvd, Suite 401, Culver City, CA 90232, USA. Contact TikTok: https://www.tiktok.com/legal/report/privacy. Privacy Policy: https://www.tiktok.com/legal/privacy-policy

9. Contact Options and Your Rights

As a data subject, you have the following rights:

Pursuant to Article 15 GDPR, you have the right to request information about the personal data we process about you to the extent specified therein.

Pursuant to Article 16 GDPR, you have the right to request the correction of inaccurate or incomplete personal data stored by us without delay.

Pursuant to Article 17 GDPR, you have the right to request the erasure of personal data stored by us, provided that the processing is not required for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims.

Pursuant to Article 18 GDPR, you have the right to request the restriction of the processing of your personal data to the extent that the accuracy of the data is disputed by you, the processing is unlawful but you oppose their erasure, or we no longer need the data, but you need it to establish, exercise, or defend legal claims, or you have objected to the processing pursuant to Article 21 GDPR.

Pursuant to Article 20 GDPR, you have the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format, or to request its transmission to another controller.

Pursuant to Article 77 GDPR, you have the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority at your usual place of residence or work, or at our company headquarters.

If you have any questions regarding the collection, processing, or use of your personal data, information, correction, restriction, or deletion of data, or withdrawal of consent given, or if you want to object to a particular use of data, please contact us directly using the contact information provided in our legal notice.

Right to Object:

If we process personal data as explained above to protect our legitimate interests that are overriding in the process of balancing of interests, you may object to such data processing with future effect. If your data is processed for direct marketing purposes, you may exercise this right at any time as described above. If your data is processed for other purposes, you have the right to object only on grounds relating to your particular situation.

After you have exercised your right to object, we will no longer process your personal data for such purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms or for the establishment, exercise, or defense of legal claims.

This does not apply to the processing of personal data for direct marketing purposes. In such a case, we will no longer process your personal data for such purposes.

Status October 2023