General information

In the following, we provide information about the collection of personal data when using our website in accordance with Art. 13 GDPR. Personal data are all data that can be related to you personally, e.g. B. Name, address, email addresses, user behavior. Responsible acc. Art. 4 para. 7 EU General Data Protection Regulation (GDPR) is Aviteo GmbH Josephspitalstraße 15 80331 München; Phone: 0049 89 - 20 17 20 16 [email protected] https://www.usenext.com/en-US/imprint You can contact our data protection officer at: [email protected]

Provision of the website and log files

a. Type and purpose of processing When you access our website, i.e. if you do not register or otherwise transmit information, information of a general nature is automatically recorded. This information (server log files) includes, for example, the type of browser, the operating system used, the domain name of your Internet service provider, your IP address and the like. This is exclusively information that does not allow any conclusions to be drawn about your person. In particular, they are processed for the following purposes: Ensuring a problem-free connection to the website, Ensuring smooth use of our website, Evaluation of system security and stability as well as for further administrative purposes. We do not use your data to draw conclusions about you personally. Information of this kind may be statistically evaluated by us in order to optimize our website and the technology behind it. b. Legal basis for processing Processing takes place in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. c. Data categories IP address, timestamp, device data, referrer, etc. d. receiver Recipients of the data are internal employees in technology, marketing, salest and, if necessary, contract processors who work as contract processors for the operation and maintenance of our website. e. Storage periods The data will be deleted as soon as it is no longer required for the purpose of the survey. For the data used to provide the website, this is generally the case when the respective session has ended. f. Statutory / contractual requirement The provision of the aforementioned personal data is not required by law or contract. Without the IP address, however, the service and functionality of our website cannot be guaranteed. In addition, individual services may not be available or restricted. g. Third country transfer The processing does not take place outside the European Union (EU) or the European Economic Area (EEA). h. Possibility of objection You have the right to object to the processing of your personal data at any time. You can inform us of your revocation at any time using the contact option given at the beginning of this data protection notice. i. Automated decision making and profiling As a responsible company, we do not use automatic decision-making or profiling in this data processing.

Use of cookies

In addition to the previously mentioned data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive assigned to the browser you are using and through which the body that sets the cookie (in this case by us) receives certain information. They are used to make the website as a whole more user-friendly and effective. We distinguish between two categories of cookies: (a) essential cookies, without which the functionality of our website would be limited, and (b) optional cookies for the purposes of website analysis and marketing. The use of optional cookies is based on your consent (Art. 6(1)(a) GDPR). In our cookie banner, we describe the optional cookies used on this website in detail. Which cookie banner do we use? This website uses the cookie consent technology from CCM19 to obtain your consent to the storage of certain cookies on your device and to document them in compliance with data protection regulations. The provider of this technology is Papoo Software & Media GmbH, Auguststr. 4, 53229 Bonn. Website: https://www.ccm19.de/en/ (hereinafter "CCM19"). When you enter our website, the following personal data is transferred to CCM19: Your consent (s) or the revocation of your consent (s) Your IP address Information about your browser Information about your device Time of your visit to the website In addition, CCM19 saves a cookie in your browser in order to be able to assign the consent given or the revocation thereof. The data collected in this way will be stored until you ask us to delete it, delete the cookie first cookie yourself or the purpose for data storage no longer applies. Mandatory statutory retention requirements remain unaffected. CCM19 is used to obtain the legally required consent for the use of cookies. The legal basis for this is Art. 6 Para. 1 S. 1 lit. c GDPR. We have concluded an order processing contract with CCM19. This is a contract prescribed by data protection law, which ensures that CCM19processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Data subject rights

If you as a user process personal data, you are considered to be the data subject according to the GDPR. Affected persons have the following rights vis-à-vis the person responsible: • Right to information (Art. 15 GDPR) • Right to correction or deletion of personal data (Art. 16, 17 GDPR) • Right to restriction of processing (Art. 18 GDPR) • Right to notification in connection with the correction or deletion of your personal data or the restriction of processing (Art. 19 GDPR) • Right to data portability (Art. 20 GDPR) • Right of objection (Art. 21 GDPR) • Right to revoke declarations of consent given. The legality of the data processing carried out up to the point of revocation remains unaffected on the basis of the previously valid consent. (Art. 7 Para. 3 GDPR) • Right to lodge a complaint with the supervisory authority (Art. 77 GDPR) You can find the competent supervisory authority for data protection issues under the following link. https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

Newsletter

a. Nature and purpose of the processing Your data will be used exclusively to send you the subscribed newsletter by e-mail. Your name is provided in order to be able to address you personally in the newsletter and, if necessary, to identify you if you wish to exercise your rights as a data subject. To receive the newsletter, it is sufficient to provide your e-mail address. When registering to receive our newsletter, the data you provide will be used exclusively for this purpose. Subscribers may also be informed by e-mail about circumstances relevant to the service or registration (for example, changes to the newsletter offer or technical circumstances). For an effective registration we need a valid e-mail address. In order to verify that a registration is actually made by the owner of an e-mail address, we use the "double-opt-in" procedure. For this purpose, we log the order of the newsletter, the sending of a confirmation e-mail and the receipt of the response requested herewith. No further data is collected. The data is used exclusively for sending the newsletter and is not passed on to third parties. If you have made a purchase of goods and/or services from us, we are entitled to send you information about our own similar goods and services via the e-mail address sent during the purchase (§ 7 III UWG). You can object to this use of your e-mail address at any time, either as a whole or for individual measures, e.g. by e-mail [email protected], without incurring any costs other than the transmission costs according to the basic rates. For sending e-mails we use the software Emarsys (www.emarsys.com). We use internal analytics about how newsletters are opened and used. The following data is evaluated as part of the analysis Newsletter ID, Click or view, date, IP address, customer number. The analysis of this data enables us to constantly improve our service offer and to adapt it to your customer wishes. b. Legal basis of the processing On the basis of your expressly given consent (Art. 6 para. 1 lit. a GDPR) or on the basis of legitimate interest (Art. 6 para. 1 lit. f GDPR) in conjunction with the requirements of §7 III UWG, we will regularly send you our newsletter or comparable information by e-mail to your specified e-mail address. c. Data categories E-mail, first-surname, customer number, language variant, IP address, etc. d. Recipients e. Storage periods The data will only be processed in this context as long as the relevant consent has been given or you have objected to the processing. After that, they will be deleted. f. Legal / contractual requirement The provision of your personal data is voluntary, solely based on your consent. Unfortunately, we cannot send you our newsletter without existing consent. g. Transfer to third countries Processing will not take place outside the European Union (EU) or the European Economic Area (EEA). h. Revocation of consent You can revoke your consent to the storage of your personal data and its use for newsletter dispatch at any time with effect for the future. In each newsletter, you will find a corresponding link for this purpose. In addition, you can also unsubscribe directly on this website at any time or inform us of your revocation using the contact option provided at the end of this privacy notice. i. Automated decision making and profiling As a responsible company, we do not use automatic decision making or profiling in this data processing.

VI. Newsletter Tracking

a. Beschreibung und Umfang der Verarbeitung personenbezogener Daten Für den Versand von E-Mails verwenden wir die Software Emarsys (www.emarsys.com). Hierfür werden folgende Daten verarbeitet: E-Mail Kundennummer Sprachvariante Vorname, Nachname Optional Artikelinformationen Gutscheincode im Fall von Aktionen Wir nutzen interne Analysemöglichkeiten darüber, wie die Newsletter geöffnet und benutzt werden. Im Rahmen der Analyse werden folgende Daten ausgewertet: Newsletter ID Klick oder View Datum IP- Adresse Kundennummer Die Auswertung dieser Daten ermöglicht uns unser Serviceangebot stetig zu verbessern und an deine Kundenwünsche anzupassen. b. Rechtsgrundlage für die Verarbeitung personenbezogener Daten Rechtsgrundlage ist Art. 6 Abs. 1 lit. a) DSGVO c. Dauer der Speicherung Die Daten werden gelöscht, sobald sie für die Erreichung des Zweckes ihrer Erhebung nicht mehr erforderlich sind. d. Widerspruchs- und Beseitigungsmöglichkeiten Du kannst den Bezug des Newsletters jederzeit stornieren. Ein entsprechender Link befindet sich in jeder E-Mail.

Registration

a. Nature and purpose of processing When you register to use our personalized services, some personal data is collected, such as name, address, contact and communication data (e.g. telephone number and e-mail address). If you are registered with us, you can access content and services that we offer only to registered users. Registered users also have the option, if necessary, to change or delete the data provided during registration at any time. Of course, we will also provide you with information about the personal data we have stored about you at any time. b. Legal basis of processing The processing of the data entered during registration is based on the user's consent to the terms of use (Art. 6 para. 1 lit. b GDPR). c. Data categories Salutation, first and last name, address, e-mail address, payment method, IP address, date and time of registration, advertising partner through which the access to the site was made d. Recipients Recipients of the data are internal employees of IT and Marketing and, if applicable, order processors who are active for the operation and maintenance of our platform. IT service providers are used to fulfill the contract. e. Storage periods Data is processed in this context only as long as the corresponding contractual agreement exists. After that, they will be deleted, provided that there are no legal retention obligations to the contrary. To contact us in this context, please use the contact details provided at the beginning of this privacy policy. f. Legal / contractual requirement The provision of your personal data is based on the user's consent to the terms of use (Art. 6 para. 1 lit. b GDPR). Without the provision of your personal data, we cannot grant you access to our offered content and services. g. Third country transfer Processing does not take place outside the European Union (EU) or the European Economic Area (EEA). h. Automated decision making and profiling As a responsible company, we do not use automated decision-making or profiling for this data processing.

Contact form and e-mail contact

a. Type and purpose of processing A contact form is available on our website, which can be used for electronic contact. If a user takes advantage of this option, the data entered in the input mask is transmitted to us and stored. This data includes e-mail address, first and last name, telephone number. For the processing of the data, your consent is obtained during the submission process and reference is made to this privacy policy. Alternatively, it is possible to contact us via the e-mail address provided. In this case, the user's personal data transmitted with the e-mail will be stored. In this context, the data will not be passed on to third parties. The data is used exclusively for processing the conversation. The other personal data processed during the sending process are used to prevent misuse of the contact form and to ensure the security of our information technology systems. Your request will be used for the purpose of improving our machine learning-based software. To this end, your request is read by our system in order to improve its quality and offer you an even better service by allocating requests more efficiently and optimizing processes. Further information can be found in our privacy policy. b. Legal basis for processing The legal basis for the processing of the data is Art. 6 (1) lit. a GDPR if the user has given his consent. The legal basis for the processing of data transmitted in the course of sending an e-mail is Art. 6 (1) lit. f GDPR. If the e-mail contact aims at the conclusion of a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR. c. Data categories E-mail address Salutation First and last name Customer number Telephone number d. Recipient Recipients of the data are internal employees of the IT and marketing department and, if applicable, order processors such as IT service providers. e. Storage periods The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. f. Legal / contractual requirement The provision of your personal data is voluntary. However, we can only process your request if you provide us with your name, e-mail address and the reason for the request. g. Third country transfer Processing does not take place outside the European Union (EU) or the European Economic Area (EEA). h. Automated decision making and profiling As a responsible company, we do not use automated decision-making or profiling for this data processing.

Payment services and payment methods

a. Description and scope of the processing of personal data In order to process payments, the following data is forwarded to the corresponding payment service providers, depending on the selected payment method: Paypal If you choose the payment method Paypal, you will automatically be redirected to the site of Paypal (PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg). The authorization and processing of the payment takes place on the website of Paypal. For the authorization at Paypal, we transmit the following data to Paypal: First name, Last name, Billing address (street, zip code, city), Delivery address (street, postal code, city), e-mail address order value The privacy policy of Paypal can be found here: https://www.paypal.com/de/webapps/mpp/ua/privacy-full Direct debit (ELV): In the case of direct debit and direct debit, we work with the following payment service providers whose privacy policies can be found here: Ixopay (https://www.ixolit.com/de/legal/privacy-policy) SEPAExpress (https://sepa.express/de/datenschutz) Ingenico (https://ingenico.com/de/legal/Datenschutzerkl%C3%A4rung) eMerchantPay (https://www.emerchantpay.com/privacy-policy/) HypoVereinsbank (https://www.hypovereinsbank.de/hvb/footer/datenschutz) Oberbank (https://www.oberbank.de/datenschutz) Postbank (https://www.postbank.de/unternehmen/ueber-uns/sicherheit-und-datenschutz/datenschutz.html) The following data will be transmitted for the purpose of payment processing: First and last name IBAN/Account number BIC/BLZ Invoice amount Invoice number Currency Invoice date E-mail address Data transmission to SCHUFA USENEXT (Aviteo GmbH) transmits personal data collected in the context of this contractual relationship regarding the application, execution and termination of this business relationship to SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden. The legal basis for these transfers is Article 6(1)(b) and Article 6(1)(f) of the General Data Protection Regulation (GDPR). Transfers on the basis of Article 6(1)(f) GDPR may only take place insofar as this is necessary to safeguard the legitimate interests of USENEXT (Aviteo GmbH) or third parties and does not outweigh the interests or fundamental rights and freedoms of the data subject that require the protection of personal data. The exchange of data with SCHUFA also serves to verify the information provided by the customer. Further information on SCHUFA's activities can be found in the SCHUFA information sheet in accordance with Art. 14 GDPR or online at www.schufa.de/datenschutz. Credit card In case of credit card payment method we cooperate with the following payment service providers, you can find their privacy policy here: Ixopay (https://www.ixolit.com/de/legal/privacy-policy) Ingenico (https://ingenico.de/payment-services/service/datenschutz) eMerchantPay (https://www.emerchantpay.com/privacy-policy/) Truevo (https://truevo.com/privacy-policy/) StreamPayments (https://streampayments.com/privacy-policy/) For the purpose of payment processing, the following data will be forwarded to our payment service providers: Credit card number CVV number Expiration date (month/year) First and last name Your address Invoice amount Currency, country Invoice date E-mail address IP address b. Legal basis for the processing of personal data The legal basis for data processing is Art. 6 para. 1 lit. b GDPR. c. Purpose of data processing The disclosure of the aforementioned data and its processing is mandatory for the performance of the contract and fraud detection and prevention. d. Duration of storage The data will be deleted as soon as they are no longer necessary to achieve the purpose for which they were collected. e. Possibilities of objection and elimination The collection of data and its storage and processing is mandatory for the execution of the contract. Therefore, there is no possibility of early objection and removal on your part. f. Automated decision making and profiling As a responsible company, we do not use automated decision-making or profiling for this data processing.

Cloudflare

We use the Content Delivery Network (CDN) of Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich Germany (Cloudflare) to increase the security and delivery speed of our website. The legal basis is our legitimate interest according to Art. 6 para. 1 lit. f GDPR. A CDN is a network of [globally] distributed servers that is able to deliver optimized content to the website user. For this purpose, personal data may be processed in server log files by Cloudflare. The recipient of your personal data is Cloudflare and acting as a processor for us. This corresponds to our legitimate interest within the meaning of Art. 6 (1) p. 1 lit. f GDPR not to operate a content delivery network ourselves. You have the right to object to the processing. Whether the objection is successful is to be determined as part of a balancing of interests. The processing of the data provided under this section is not required by law or contract, but the functionality of the website is not guaranteed without the processing. Your personal data will be stored by Cloudflare for as long as necessary for the purposes described. For more information on objection and removal options vis-à-vis Cloudflare, please see: Cloudflare DPA Cloudflare has implemented compliance measures for international data transfers. These apply to all global activities where Cloudflare processes personal data of individuals in the EU. These measures are based on the EU Standard Contractual Clauses (SCCs). For more information, please visit: https://www.cloudflare.com/cloudflare_customer_SCCs-German.pdf

Google Analytics

a. Type and purpose of processing This website uses Google Analytics, a web analysis service from the Google Building Gordon House, 4 Barrow Street, Dublin, D04 E5W5, Ireland. Google Analytics uses so-called "cookies", ie text files that are stored on your computer and that enable your use of the website to be analyzed. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there. However, due to the activation of IP anonymization on this website, your IP address will be shortened beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. The full IP address is only transmitted to a Google server in the USA and shortened there in exceptional cases. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide the website operator with other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. The purpose of data processing is to evaluate the use of the website and to compile reports on activities on the website. Based on the use of the website and the Internet, further related services are then to be provided. b. Legal basis for processing The data entered is processed on the basis of the user's consent (Art. 6 Para. 1 lit. a GDPR). c. Data categories IP address (shortened/anonymized) d. receiver Employees of the sales and marketing department of the own company Google Building Gordon House, 4 Barrow Street, Dublin, D04 E5W5, Ireland e. Storage periods In this context, data is only processed as long as the relevant consent is available. They will then be deleted unless there are any statutory retention requirements. To contact us in this context, please use the contact details given at the beginning of this data protection declaration. f. Statutory / contractual requirement The provision of your personal data is voluntary, based solely on your consent. If you prevent access, this can lead to functional restrictions on the website. g. Third country transfer The processing also takes place outside the European Union (EU) or the European Economic Area (EEA). In order to guarantee the level of data protection in this third country, we have concluded the standard data protection clauses with Google (Analytics). h. Revocation of Consent You can revoke your consent to the storage of your personal data at any time with effect for the future. You can prevent the storage of cookies by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by downloading and installing the available browser plug-in: " Browser add-on to deactivate Google Analytics ". i. Automatic decision making and profiling With the help of the tracking tool Google Analytics, the behavior of the website visitors can be evaluated and the interests analyzed. To do this, we create a pseudonymous user profile.

Hotjar

a. Nature and purpose of processing We use Hotjar to better understand the needs of our users and to optimize the experience on this website. Using Hotjar's technology, we get a better understanding of our users' experiences (e.g., how much time users spend on which pages, which links they click on, what they like and dislike, etc.) and this helps us tailor our offerings based on our users' feedback. Hotjar works with cookies and other technologies to collect information about our users' behavior and about their devices (in particular, device IP address (collected and stored only in anonymized form), screen size, device type (unique device identifiers), information about the browser used, location (country only), language preferred to view our website). Hotjar stores this information in a pseudonymized user profile. The information is neither used by Hotjar nor by us to identify individual users or merged with other data about individual users. For more information, please see Hotjar's privacy policy (https://www.hotjar.com/legal/policies/privacy). b. Legal basis of the processing The processing of the entered data is based on the user's consent (Art. 6 para. 1 lit. a GDPR). c. Data categories Timestamp, IP address, etc. d. Recipients Recipients of the data are internal employees of Marketing and IT and hotjar as order processor. For this purpose, we have concluded the corresponding order processing agreement with hotjar. e. Storage periods Data will only be processed in this context as long as the corresponding consent has been given. Afterwards, they will be deleted, provided that there are no legal storage obligations to the contrary. To contact us in this context, please use the contact details provided at the beginning of this privacy policy. f. Legal / contractual requirement The provision of your personal data is voluntary, based solely on your consent. If you prevent access, this may result in functional restrictions on the website. g. Third country transfer The processing does not take place outside the European Union (EU) or the European Economic Area (EEA), as the registered office of Hotjar Ltd is located in Malta. h. Withdrawal of consent You can revoke your consent to the storage of your personal data at any time with effect for the future. You can object to the storage of a user profile and information about your visit to our website by Hotjar, as well as to the setting of Hotjar tracking cookies on other websites, by clicking on this opt-out link (https://www.hotjar.com/legal/compliance/opt-out). i. Automated decision making and profiling The tracking tool hotjar can be used to evaluate the behavior of visitors to the website and analyze their interests. For this purpose, we create a pseudonymous user profile.

Google AdWords und Google Display Network

a. Nature and purpose of the processing Our website uses Google conversion tracking. The operating company of the Google AdWords services is Google Building Gordon House, 4 Barrow Street, Dublin, D04 E5W5, Ireland. If you have reached our website via an ad placed by Google, Google AdWords will set a cookie on your computer. The conversion tracking cookie is set when a user clicks on an ad placed by Google. If the user visits certain pages of our website and the cookie has not yet expired, we and Google can recognize that the user clicked on the ad and was redirected to this page. Each Google AdWords customer receives a different cookie. Cookies can therefore not be tracked through the website of AdWords customers. The information obtained using the conversion cookie is used to create conversion statistics for AdWords customers who have opted for conversion tracking. Customers learn the total number of users who clicked on their ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information that personally identifies users. Each time you visit our website, personal data, including your IP address, is transferred to Google in the USA. This personal data is stored by Google. Google may pass on this personal data collected via the technical process to third parties. Our company does not contain any information from Google by means of which the data subject could be identified. b. Legal basis of the processing We process users' personal data only in compliance with the relevant data protection regulations. This means that the users' data is only processed if a legal permission exists. The legal basis for the integration of Google AdWords and the associated data transfer to Google is your consent (Art. 6 para. 1 lit. a GDPR). c. Data categories IP address d. Recipients Employees of the marketing and sales departments as well as Google as order processor e. Storage periods Data will only be processed in this context as long as the corresponding consent has been given. Afterwards, they are deleted unless there are legal retention obligations to the contrary. These cookies lose their validity after 30 days and are not used for personal identification. f. Legal / contractual requirement The provision of your personal data is voluntary, based solely on your consent. If you prevent access, this may result in functional restrictions on the website. g. Third country transfer Processing also takes place outside the European Union (EU) or the European Economic Area (EEA). To ensure the level of data protection in this third country, we have concluded standard data protection clauses with Google AdWords. h. Revocation of consent You can revoke your consent to the storage of your personal data at any time with effect for the future. If you do not wish to participate in tracking, you can refuse the setting of a cookie required for this - for example, by means of a browser setting that generally deactivates the automatic setting of cookies or by setting your browser so that cookies from the domain "googleleadservices.com" are blocked. Please note that you may not delete the opt-out cookies as long as you do not want any measurement data to be recorded. If you have deleted all your cookies in the browser, you must set the respective opt-out cookie again. i. Automated decision making and profiling As a responsible company, we do not use automated decision-making or profiling when using Google AdWords.

Advertising and Marketing Services

Facebook, Custom Audiences and Facebook Marketing Services Within our online offer, the so-called "Facebook pixel" of the social network Facebook, which is operated by Meta Platforms Inc., 1 Hacker Way, Menlo Park, CA 94025, USA, or if you are a resident of the EU, Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Facebook"), is used for the analysis, optimization and economic operation of our online offer. With the help of the Facebook pixel, it is possible for Facebook, on the one hand, to determine the visitors to our online offer as a target group for the display of advertisements (so-called "Facebook ads"). Accordingly, we use the Facebook pixel to display the Facebook ads placed by us only to those Facebook users who have also shown an interest in our online offer or who have certain characteristics (e.g. interests in certain topics or products determined on the basis of the websites visited) that we transmit to Facebook (so-called "Custom Audiences"). With the help of the Facebook pixel, we also want to ensure that our Facebook ads correspond to the potential interest of users and do not have a harassing effect. With the help of the Facebook pixel, we can also track the effectiveness of the Facebook ads for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Facebook ad (so-called "conversion"). The Facebook pixel is integrated by Facebook after your consent and can save a so-called cookie, i.e. a small file, on your device. If you subsequently log in to Facebook or visit Facebook while logged in, the visit to our online offer will be noted in your profile. The data collected about you is anonymous for us, so it does not offer us any conclusions about the identity of the user. However, the data is stored and processed by Facebook, so that a connection to the respective user profile is possible and can be used by Facebook and for its own market research and advertising purposes. If we should transmit data to Facebook for matching purposes as part of the pixel process, this data is encrypted locally on the browser and only then sent to Facebook via a secure https connection. This is done solely for the purpose of establishing a match with the data equally encrypted by Facebook. The legal basis for the use of Facebook Pixel is Art. 6 para. 1 lit. b GDPR. The processing of the data by Facebook takes place within the framework of Facebook's data usage policy. Accordingly, general information on the display of Facebook ads, in Facebook's data usage policy: https://www.facebook.com/policy.php. Specific information and details about the Facebook Pixel and how it works can be found in Facebook's help section: https://www.facebook.com/business/help/651294705016616. You can also change the use of cookies by setting your browser software accordingly or in the cookie settings. To set which types of advertisements are displayed to you within Facebook, you can visit the page set up by Facebook and follow the instructions there on the settings for usage-based advertising: https://www.facebook.com/settings?tab=ads. The settings are platform-independent, i.e. they are applied to all devices, such as desktop computers or mobile devices. Provision of offers by Sovendus GmbH a. Nature and purpose of the processing Provision of offers of Sovendus GmbH Special offers / voucher offers In order to select an advantage offer/voucher offer that is currently of interest to you regionally, we will transmit your postal code and e-mail address in encrypted form to Sovendus GmbH, Hermann-Veit-Str. 6, 76135 Karlsruhe (Sovendus). The e-mail address will also be used to take into account any objection to advertising by Sovendus. The IP address is used by Sovendus exclusively for data security purposes and is usually anonymized after seven days. In addition, for billing purposes, we transmit pseudonymized order number, order value with currency, session ID, coupon code and time stamp to Sovendus. As far as necessary for the respective advantage offer / coupon offer, when you click on the offer, we transmit your name, address data, e-mail address and/or telephone number to Sovendus in encrypted form for the preparation of the personalized request for the advantage offer from the product provider. By clicking on the advantage offer from Sovendus, you consent to the transmission of your name, address data, e-mail address and/or telephone number in encrypted form to the product provider for the preparation of the personalized request for the advantage offer. For further information on the processing of your data by Sovendus, please refer to the online privacy policy at www.sovendus.de/datenschutz. b. Legal basis for data processing The processing of the transmitted data is based on your consent (Art. 6 para. 1 lit. a GDPR). c. Data categories Postal addresses, email addresses, telephone numbers, name, IP address, order number, order value with currency, session ID, coupon code and time stamp. d. Recipients Recipients of the Data are internal IT staff and Sovendus as processor (and the respective product providers). e. Duration of storage You have the option to revoke your consent to the processing of personal data at any time. f. Legal / contractual requirement The provision of your personal data is voluntary. Without the provision of your personal data, we cannot grant you access to offered content and services. g. Third country transfer Processing does not take place outside the European Union (EU) or the European Economic Area (EEA). h. Revocation of consent You can revoke your consent to the storage of your personal data at any time with effect for the future. You can notify us of your revocation at any time using the contact option provided at the beginning of this privacy notice. i. Automated decision-making and profiling As a responsible company, we do not use automated decision-making or profiling for this data processing. Retargeting usemax advertisement is an offer of Emego GmbH, Sandstraße 87, 40789 Monheim am Rhein, Germany. When the USENEXT website is called up, a cookie is set for the user via the usemax ad server, which contains a reference to the user's surfing behavior. The information collected via this cookie is used to address the user in an individualized and personalized manner via the website or via advertising placements on third-party websites that are connected to usemax. The user can delete his collected data via the following link: https://www.usemax.de/index.php?l=rm&kunde=&id=1. Via this link, an opt-out cookie is set by the browser. If you delete the opt-out cookie, the data collection will start again on your next visit. The objection therefore only applies to the device and the web browser on which the opt-out cookie was stored. The legal basis for the use of usemax advertisement is Art. 6 para. 1 lit. a GDPR. DoubleClick Floodline DoubleClick Floodline is a service provided by Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as "Google"). DoubleClick uses cookies (so-called "floodlights") to present you with targeted, relevant advertisements. Often, the cookies are used to serve ads that are relevant to you, to improve campaign performance reports, or to prevent you from seeing the same ad multiple times. DoubleClick assigns a pseudonymous ID to your browser for this purpose. This cookie ID is used, among other things, to enable DoubleClick to record, for example, which ads are to be served in which browser. Likewise, DoubleClick can use cookie IDs to record conversions that are related to the ad requests. The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. DoubleClick Floodlight cookies do not contain any personal data. The information generated by the cookies is transferred by Google to a server in the USA for evaluation and stored there. A transfer of data by Google to third parties only takes place due to legal regulations. If you have a Google account, the information linked to the DoubleClick cookie can be added to your Google account with your authorization. You can read more information about the DoubleClick floodlight cookie here: https://support.google.com/searchads/answer/2839090?hl=de. The legal basis for the processing of your data is your consent pursuant to Art. 6 (1) a) GDPR. You can revoke or adjust your consent at any time with effect for the future. DoubleClick We use "DoubleClick" on our website, an online marketing tool of Google Ireland Limited, Google Building Gordon House, Barrow St, Dublin 4, Ireland (hereinafter referred to as "Google"). DoubleClick uses, among other things, cookies, which are small text files that are stored locally in the cache of your web browser on your terminal device. Google uses a cookie ID to record which ads are displayed in which web browser. This can prevent ads from being displayed more than once. DoubleClick can also use the cookie IDs to record so-called conversions that are related to ad requests. This is the case, for example, when you see a DoubleClick ad and later call up the advertiser's website with the same web browser and make a purchase there. According to information from Google, the aforementioned cookies do not contain any personal data. By using DoubleClick, your browser automatically establishes a direct connection with Google's server. We have no influence on the scope and further use of the data collected by Google through the use of DoubleClick. According to our knowledge, Google receives the information that you have called up the relevant part of our website or clicked on an advertisement from us. If you have a user account with Google and are registered, Google can assign the visit to your user account. Even if you are not registered with Google or have not logged in, there is a possibility that the Google stores your IP address. We use DoubleClick to serve ads that are relevant and interesting to you, to improve campaign performance reports, or to prevent you from seeing the same ads more than once. The legal basis for the processing and transmission of data to the third-party provider is your consent pursuant to Art. 6 para. 1 lit. a) GDPR. You can prevent the installation of cookies by deleting existing cookies and disabling the storage of cookies in the settings of your web browser. We point out that in this case you may not be able to use all features of our website in full. It is also possible to prevent the storage of cookies by setting your web browser to block cookies from the domain "www.googleadservices.com" (https://adssettings.google.de). We would like to point out that this setting will be deleted when you delete your cookies. In addition, you can deactivate interest-based ads via the link https://optout.aboutads.info. We would like to point out that this setting will also be deleted when you delete your cookies. For more information on data use by Google, on setting and objection options, and on data protection, please visit the following Google website : https://policies.google.com/privacy?hl=de&gl=de DoubleClick Ad Exchange We use "Doubleclick Ad Exchange", a web advertising service from Google, on our website. Doubleclick Ad Exchange uses cookies, among other things. The information stored in the cookies can be recorded and evaluated by Google or by third parties. In addition, Doubleclick Ad Exchange also uses so-called "WebBacons" to collect information. These are small invisible graphics that can be used to record and analyze user behavior and visitor traffic on the website. The information generated by this about the use of our website is transmitted to a Google server in the USA and stored there. Google uses this information to evaluate your usage behavior. In this context, the IP address of the user may also be transmitted and stored. This transmission only takes place for the purpose of combating spam and / or fraud, for example in cases of ad impression spam or click spam. According to Google, this data is only accessible to the so-called anti-abuse teams. According to information from Google, the IP address is not associated with other data stored by Google. The legal basis for the processing is your consent pursuant to Art. 6 (1) a) GDPR, as well as our legitimate interest in the processing of the above data by the third-party provider pursuant to Art. 6 (1) f) GDPR. You can prevent the installation of cookies by deleting existing cookies and deactivating a storage of cookies in the settings of your web browser. We point out that in this case you may not be able to use all features of our website in full. It is also possible to prevent the storage of cookies by setting your web browser to block cookies from the domain "www.googleadservices.com" (https://www.google.de/settings/ads). We would like to point out that this setting will be deleted when you delete your cookies. In addition, you can deactivate interest-based ads via the link http://www.aboutads.info/choices. Also note that this setting will also be deleted when you delete your cookies. Interactive Performance This website uses technology from Interactive Performance Deutschland GmbH, Hohe Brücke 1, D-20459 Hamburg, Germany, to collect and store data about your usage behavior on our website for optimization and marketing purposes. This data is used to analyze visitor behavior and is used to create pseudonymous usage profiles. Cookies are used for this purpose, which enable recognition of an Internet browser on a repeat visit. Interactive Performance GmbH processes IP addresses and cookie IDs on our behalf in this context. The IP addresses of visitors are shortened before storage, so that a reference to persons is excluded and a combination of usage profiles to IP addresses is no longer possible. The legal basis for the processing of your data is your consent pursuant to Art. 6 (1) a) GDPR. You can revoke or adjust your consent at any time with effect for the future. For more information, please see the privacy policy of Interactive Persormance GmbH: https://interactiveperformance.de/kontakt/datenschutz//

Facebook Fanpage

Aviteo GmbH operates an online presence on Facebook, a so-called Facebook fan page. When visiting our fan page, the following information on data processing also applies. General information on data protection on Facebook can be found here (https://www.facebook.com/about/privacy/). 1. Joint responsibility, contact details, company data protection officer: We are jointly responsible with Facebook for the operation of our Facebook fan page in accordance with Art. 26 GDPR. For this purpose, we have stipulated in an agreement with Facebook who fulfills which obligations with regard to data protection. This agreement can be found here (https://www.facebook.com/legal/terms/page_controller_addendum). According to this, Facebook is primarily responsible for providing the data subject with information about the joint processing and enabling them to exercise their data protection rights. Regardless of this, we are hereby informing you about your visit to our fan page. Our contact details are: Aviteo GmbH Josephspitalstraße 15, 80331 München [email protected] You can reach Facebook at: Meta Platforms Ireland Ltd. 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland You can reach Facebook online here (https://www.facebook.com/help/contact/2061665240770586) You can contact our company data protection officer at: [email protected] You can contact Facebook's data protection officer at https://www.facebook.com/help/contact/540977946302970. 2. Collection and storage of personal data as well as type and purpose and their use: a) Data collected by Facebook: If you are a Facebook user, Facebook collects the data described in the Facebook data policy under “What types of information do we collect?”. If you are not a Facebook user, you may be able to Cookies, small text files, which are nevertheless provided with identifiers, are stored in your browser, which enable so-called tracking of your user behavior. As a rule, when you visit Facebook, Facebook also processes user data for market research and advertising purposes. Based on user behavior (including when visiting our fan page), complex user profiles are created that Facebook can use to display personalized advertisements to visitors inside and outside Facebook. You can also find more information on this in the Facebook data policy. If you do not agree to this, you can object here (opt-out). b) Data used by us ("page insights") and legal basis: Facebook provides us with statistics and usage data that we can use to analyze the use of our fan page (so-called "page insights"). This enables us to continuously improve our offer on Facebook. As the operator, we do not make any decisions regarding the processing of Insights data and all other information resulting from Art. 13 GDPR, such as Storage duration of cookies on user devices. The primary responsibility according to the GDPR for the processing of Insights data lies with Facebook and Facebook fulfills all obligations under the GDPR with regard to the processing of Insights data. As page administrators, we have no other option, not even via user tracking, to evaluate user behavior on our fan page. In principle, it is also not possible for us to identify the visitor to the fan page based on the page insights. In particular, according to the agreement, we have no right to require Facebook to disclose individual visitor data. Identification is only possible for us if we can assign individual profile pictures to “like” information for the page; but only if our fan page has been marked with "Like" by the corresponding visitor and the "Like" information is set to "public". You can find out what information Facebook uses to create page insights here. The operation of the Facebook fan page and the use of the page insights serve our legitimate interest in an effective external presentation and efficient communication with our customers and interested parties. This interest justifies the operation of the site both in relation to the legitimate interests of Facebook users and in relation to visitors to our fan page who do not have a Facebook account. The legal basis is accordingly Art. 6 Para. 1 lit. f) GDPR. 3. Transfer of data to third parties: Data collected by Facebook is exchanged and processed within the entire Facebook group. The Facebook group also includes Instagram, WhatsApp and Oculus, for example. For example, information collected via Facebook is used to show the user personalized advertising on Instagram, or information from WhatsApp is used to take action on Facebook against accounts that send spam via WhatsApp. You can find this information in the Facebook data policy under “How do the Facebook companies work together?”. When processing data by Facebook, it can happen that user data is transferred outside of the European Economic Area (EEA), in particular the USA. 4. Right of objection: If your personal data is based on legitimate interests in accordance with Art. 6 Para. 1 lit. f GDPR are processed, you have the right to object to the processing of your personal data in accordance with Art. 21 GDPR, provided there are reasons for this that arise from your particular situation or the objection is directed against direct mail. In the latter case, you have a general right of objection, which we will implement without specifying a particular situation. If you would like to exercise your right of withdrawal or objection, an email to [email protected] is sufficient. 5. Rights of data subjects: You have the right to withdraw your consent to us at any time. As a result, we are no longer allowed to continue the data processing based on this consent in the future. In addition, you have the right to information under Art. 15 GDPR, the right to correction under Art. 16 GDPR, the right to erasure under Art. 17 GDPR, the right to restriction of processing under Art. 18 GDPR, and the right to Data portability based on Art. 20 GDPR. Furthermore, there is a right of appeal to a competent data protection supervisory authority (Art. 77 GDPR). In principle, you can assert your data subject rights against both Facebook and us. Since only Facebook has direct access to your user data, you can most effectively assert your data subject rights against Facebook.

Facebook Messenger

a. Description and scope of data processing You can contact us via Facebook Messenger. This is an offer of Meta Platforms Ireland Ltd, 4 Grand Canal Square Grand Canal Harbour, Dublin 2, Ireland. By installing and using the messenger on your smartphone, you agree to the terms and conditions of Meta Platforms Ireland Ltd. Unfortunately, we have no influence on these or on the privacy policy of Meta Platforms Ireland Ltd. You can find more information as well as the privacy policy of Facebook here: https://www.facebook.com/about/privacy/ If you contact us via Facebook Messenger, the data will be used exclusively for processing the conversation. In this context, the data will not be passed on to third parties. The data will not be used for advertising purposes. b. The following data will be processed: The ID of your Facebook profile Your Facebook username Your first and last name If applicable, your e-mail address c. Legal basis for data processing The legal basis for the processing of data is Art. 6 para. 1 lit. a GDPRif the user has given his consent. The legal basis for the processing of data transmitted in the course of sending a request is Art. 6 (1) lit. f GDPR. d. Purpose of the data processing The processing of personal data from Facebook Messenger serves us solely to process the contact. e. Duration of storage, possibility of revocation and removal. You have the option to revoke your consent to the processing of personal data at any time. If you contact us, you can object to the storage of personal data at any time. In such a case, the conversation cannot be continued. All personal data stored by us in the course of contacting you will be deleted in this case. We have no influence on the deletion of data at Meta Platforms Ireland Ltd.

Manychat

a. Description and scope of data processing For automated communication via messenger services, we use the third-party tool ManyChat a: ManyChat Inc, [email protected], 220 Golden Oak Dr, Portola Valley, CA, 94028, manychat.com. In addition to individual and pre-structured chats, we also use ManyChat to register and send a newsletter via Facebook Messenger. In doing so, the data and content of the communication is processed via servers in the USA and exchanged with Facebook Messenger. Unfortunately, we have no influence on the applicable privacy policy of ManyChat Inx. You can find more information and the privacy policy of ManyChat here: https://manychat.com/privacy.html We have concluded an order processing contract with ManyChat, as well as agreed to the application of the EU standard contractual clauses to ensure the GDPR-compliant use of the service. The following data is processed in the process: The ID of your Facebook profile Your Facebook username Your first and last name If applicable, your e-mail address b. Legal basis for data processing The legal basis for the processing of the data is Art. 6 (1) lit. a GDPRif the user has given his consent. In the absence of consent, the legal basis for processing the data is also our legitimate interest in direct marketing pursuant to Art. 6 (1) lit. f GDPR. Consent to data processing and analysis for the processing of customer communications is given within Facebook Messenger by opt-in. Consent to the newsletter dispatch takes place within Facebook Messenger by active consent of the user in. It is logged in the chat history in order to be able to provide proof of consent. c. Purpose of data processing The processing of personal data within ManyChat serves the purpose of processing and automating customer relations. In this context, user inputs and actions in Facebook Messenger are evaluated by us, stored and treated as strictly confidential within our company. d. Duration of storage, possibility of revocation and elimination You have the option to revoke your consent to the processing of personal data at any time. If you contact us, you can object to the storage of his personal data at any time. In such a case, the conversation can not be continued. You have the option to revoke your consent to the newsletter mailing at any time by sending the word "Stop" or "Unsubscribe" in the chat or by navigating through the main menu offered to unsubscribe. All personal data stored by us in the course of contacting you will be deleted in this case. We have no influence on a deletion of the data at Facebook Ireland Ltd.

Instagram Online Presence

a. Nature and purpose of the processing We appreciate your interest in our presence on Instagram. We would like to give you an overview of what data is collected, used and stored by us there. Social networks can usually comprehensively analyze your user behavior when you visit their website or a website with integrated social media content (e.g. Like buttons or advertising banners). By visiting our social media presence on Instagram, numerous processing operations relevant to data protection are triggered. In detail: If you are logged into your Instagram account and visit our social media presence, Instagram can assign this visit to your user account. However, your personal data may also be collected under certain circumstances if you are not logged in or do not have an account on Instagram. In this case, this data collection takes place, for example, via cookies that are stored on your end device or by recording your IP address. With the help of the data collected in this way, Instagram can create user profiles in which your preferences and interests are stored. In this way, you can be shown interest-based advertising inside and outside of Instagram. If you have an account on Instagram, the interest-based advertising can be displayed on all devices on which you are logged in or have been logged in. Please also note that we cannot track all processing on Instagram. Therefore, additional processing operations may be carried out by Instagram. For details, please refer to Instagram's terms of use and privacy policy. b. Legal basis of the processing The processing is carried out pursuant to Art. 6 para. 1 lit. f. GDPRon the basis of our legitimate interest of contacting our customers. The analysis processes initiated by Instagram may be based on deviating legal bases to be indicated by Instagram (e.g. consent within the meaning of Art. 6 (1) lit. a GDPR). c. Data categories Which specific data is collected and how it is used can be found in Instagram's privacy policy: Instagram: https://help.instagram.com/155833707900388 d. Recipients Employees of the IT department of your own company Instagram (meta) e. Storage periods After the end of the purpose and the end of the use of Instagram by us, the data collected in this context will be deleted. f. Legal / contractual requirement. The provision of your personal data is voluntary. Without the provision of your personal data, we cannot grant you access to our offered content and services. g. Third country transfer Processing does not take place outside the European Union (EU) or the European Economic Area (EEA). h. Revocation of consent You can revoke your consent to the storage of your personal data at any time with effect for the future. You can notify us of your revocation at any time using the contact option provided at the beginning of this privacy notice. i. Automated decision-making and profiling As a responsible company, we do not use automated decision-making or profiling for this data processing.

Google Tag Manager

Use of Google Tag Manager: Google Tag Manager is a solution that allows marketers to manage website tags through one interface. The Tag Manager tool itself (which implements the tags) is a cookie-less domain and does not collect any personal data. The tool takes care of triggering other tags, which in turn may collect data. Google Tag Manager does not access this data. If a deactivation has been made at the domain or cookie level, it will remain in place for all tracking tags implemented with Google Tag Manager: http://www.google.de/tagmanager/use-policy.html. b. Legal basis of the processing The processing of the entered data is based on the user's consent (Art. 6 para. 1 lit. a GDPR). c. Data categories IP address d. Recipients Recipients of the data are internal employees of the IT and marketing department and Google as a processor. For this purpose, we have concluded the corresponding order processing agreement with Google. e. Storage periods Data will only be processed in this context as long as the corresponding consent has been given. Afterwards, they will be deleted, provided that there are no legal storage obligations to the contrary. To contact us in this context, please use the contact details provided at the beginning of this privacy policy. f. Legal / contractual requirement The provision of your personal data is voluntary, based solely on your consent. If you prevent access, this may result in functional restrictions on the website. g. Third country transfer Processing also takes place outside the European Union (EU) or the European Economic Area (EEA). To ensure the level of data protection in this third country, we have concluded standard data protection clauses with Google. h. Revocation of consent You can revoke your consent to the storage of your personal data at any time with effect for the future. You can notify us of your revocation at any time using the contact option provided at the beginning of this privacy notice. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. i. Profiling The Google Tag Manager tool can be used to evaluate the behavior of visitors to the website and analyze their interests.

BytePlant

a. Nature and purpose of processing The data you provide in the context of an order may be used to verify whether there is an atypical order transaction (e.g. simultaneous ordering of a large number of goods to the same address using different customer accounts). In principle, we have a legitimate interest in carrying out such a check. The legal basis for the processing is Art. 6(1)(f) GDPR. To prevent fraud, we use the services of BytePlant GmbH Software Solutions & Consulting, Heilsbronner Strasse 4, D-91564 Neuendettelsau (hereinafter "BytePlant") to operate our website. BytePlant collects and processes data with the help of cookies and other tracking technologies to determine the terminal device used by the user and other data about the use of the website. An assignment to a specific user does not take place. To the extent that IP addresses are collected by BytePlant, they are immediately encrypted. The data is stored by BytePlant in a fraud prevention database. The database also stores data transmitted by us to BytePlant on end devices that have already been used for (attempted) fraud. In this respect, too, there is no allocation to specific users. In the course of an order process on our website, we retrieve a risk assessment of the user's terminal device from the BytePlant database. This risk assessment on the probability of a fraud attempt takes into account, among other things, whether the terminal device has dialed in via different service providers, whether the terminal device has a frequently changing geo-reference, how many transactions have been made via the terminal device and whether a proxy connection is used. The legal basis for the processing is Art. 6(1)(f) GDPR. b. Legal basis of the processing The processing of the transmitted data is based on our legitimate interests to prevent fraud (Art. 6(1)(f) GDPR). c. Data categories Past addresses, email addresses, telephone numbers. d. Recipients Recipients of the data are internal employees of IT and BytePlant as order processor. For this purpose, we have concluded the corresponding order processing agreement with BytePlant. e. Storage periods Data is only processed for 14 days in this context. After that, they will be deleted, provided that there are no legal retention obligations to the contrary. To contact us in this context, please use the contact details provided at the beginning of this privacy policy. f. Legal / contractual requirement In principle, a data subject cannot make use of any right to object to the processing of personal data in connection with fraud prevention. g. Third country transfer Processing takes place exclusively in the European Union (EU) or the European Economic Area (EEA). h. Profiling No profiling takes place.

Google Remarketing

a. Nature and purpose of the processing This website uses the remarketing function of Google Inc. The operator of the Google Remarketing services is Google Building Gordon House, 4 Barrow Street, Dublin, D04 E5W5, Ireland. The function is used to present interest-based advertisements to website visitors within the Google advertising network. A so-called "cookie" is stored in the browser of the website visitor, which makes it possible to recognize the visitor when they visit websites that belong to Google's advertising network. On these pages, the visitor may be presented with advertisements that relate to content that the visitor has previously viewed on websites that use Google's remarketing function. Each time you visit our website, personal data, including your IP address, is transferred to Google in the USA. This personal data is stored by Google. Google may pass on this personal data collected via the technical process to third parties. Our company does not contain any information from Google by means of which the data subject could be identified. b. Legal basis of the processing The legal basis for the integration of Google Remarketing and the associated data transfer to Google is your consent (Art. 6 para. 1 lit. a GDPR). c. Data categories IP address, user ID, timestamp, device data, etc. d. Recipients Recipients of the data are internal employees of the marketing and IT departments and Google as a processor. e. Storage periods Data will only be processed in this context as long as the corresponding consent has been given. After that, they will be deleted, provided that there are no legal retention obligations to the contrary. To contact us in this context, please use the contact details provided at the beginning of this privacy policy. f. Legal / contractual requirement The provision of your personal data is voluntary, based solely on your consent. If you prevent access, this may result in functional restrictions on the website. g. Third country transfer Google processes your data in the USA. To ensure the level of data protection in this third country, we have concluded standard data protection clauses with Google. h. Revocation of consent If you do not wish to use Google's remarketing function, you can generally deactivate it by making the appropriate settings at https://support.google.com/adwordspolicy/answer/143465. Alternatively, you can deactivate the use of cookies for interest-based advertising via the advertising network initiative by following the instructions at http://www.networkadvertising.org/managing/opt_out.asp. You can revoke your consent to the storage of your personal data at any time with effect for the future. i. Automated decision making and profiling As a responsible company, we do not use automated decision-making or profiling for this data processing.

Oliro

a. Nature and purpose of processing This website uses the performance advertising network of Oliro GmbH. Gredinger Str. 28, 90453 Nuremberg. Through Oliro, commercial operators of websites, so-called merchants, can display their advertisements on websites of third parties, the publishers. To enable the correct allocation of transactions and thus the calculation of commission payments between merchant and publisher, Oliro stores cookies on the end devices of users who visit its customers' websites. In the process, personal data is processed pseudonymously. Oliro uses cookies from other service providers for its activities, including Neory GmbH, The Trade Desk, Active Agend AG and Adform A/S. You can view the provider's privacy policy at https://oliro.com/datenschutz/. b. Legal basis of the processing The processing of the transmitted data is based on your consent to carry out a performance-based paid online advertising campaign "Advertising" in accordance with Art. 6 para. 1 lit. a) GDPR. c. Data categories IP address, journey tag, attributes of the browser or device, etc. d. Recipients Recipients of the data are internal employees of Aviteo and Oliro as order processors. For this purpose, we have concluded the corresponding order processing agreement with the provider. e. Storage periods We store your personal data only for as long as is necessary, on the one hand, to implement the purposes for which we collected it and, on the other hand, to comply with legal accounting and reporting requirements. To contact us in this regard, please use the contact details provided at the beginning of this Privacy Policy. f. Legal / contractual requirement The provision of your personal data is voluntary, based solely on your consent. In principle, a data subject may exercise your right of withdrawal when processing personal data. g. Third country transfer Processing takes place exclusively in the European Union (EU) or the European Economic Area (EEA). h. Withdrawal of consent You can revoke your consent to the storage of your personal data at any time with effect for the future. You can notify us of your revocation at any time using the contact option provided at the beginning of this privacy notice. i. Automated decision-making and profiling As a responsible company, we do not use automated decision-making or profiling for this data processing.

Trustpilot

We use the rating portal Trustpilot, which is operated by TrustPilot A/S, Pilestraede 58, 5th floor, 1112 Copenhagen, Denmark. Trustpilot offers users the opportunity to rate our services, for which they are asked for their consent. Once you have given your consent, you will receive a rating request with a link to a rating page. For this purpose, your surname, first name, email address and order number (reference number) are transmitted to Trustpilot for clear assignment. This data is neither used Trustpilot itself nor passed on to third parties. The submission of the rating is voluntary. The legal basis for processing the user's data as part of the rating process is consent pursuant to Art. 6 para. 1 lit. a. GDPR. In order to submit a rating, it is necessary to open a customer account with Trustpilot. In this case, the data protection provisions and general terms and conditions of Trustpilot apply. These can be viewed under the following link: In addition, the Trustpilot widget is integrated on our website. This gives you a first impression of the quality of our products and displays a selection of reviews from our customers and the overall score formed from all reviews. The voluntary reviews are published, under a clear name or under self-selected pseudonyms. A widget is a function and content element integrated within our online offer that displays variable information. The corresponding content is retrieved from the servers of Trustpilot. This is the only way to always display the current rating. For this purpose, a data connection is established from the website accessed within our online offer to Trustpilot and Trustpilot receives certain technical data (access data, including the IP address), which are necessary so that the content can be delivered. Furthermore, Trustpilot receives information that users have visited our online offer. This information may be stored in a cookie and used by Trustpilot to identify which online offers participating in the Trustpilot rating process have been visited by the user. The information may be stored in a user profile on Trustpilot and used for advertising or market research purposes. If we ask users to consent to the processing of their data through the use of cookies, the legal basis for the processing is Art. 6 para. 1 lit. a. GDPR. Insofar as the processing of the user's data in the context of the integration of the widget is concerned, the legal basis is our legitimate interest in informing our users about the quality of our services pursuant to Art. 6 para. 1 lit. f. GDPR. For more information about the processing of your data by Trustpilot, as well as about your rights to object and other data subject rights, please see Trustpilot's privacy policy: http://en.legal.trustpilot.com/end-user-privacy-terms

Adobe Typekit

a. Nature and purpose of the processing This website uses so-called web fonts for the uniform display of fonts. When you call up a web page, your browser reloads the required web fonts in order to display texts and fonts correctly. For the display of these web pages, web fonts from Adobe Systems Inc. (USA), San Jose, California, from the Typekit service are used. Adobe Systems Inc. thereby receives information about your IP address, the calling domain and the requested font. For more information about the information Adobe collects, please visit: https://www.adobe.com/privacy/policies/typekit.html. Adobe maintains an office in the Union. The company is Adobe Systems Software Ireland Limited, Managing Director Mark Higgins, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Republic of Ireland. For more information on how Adobe handles user data, please see Adobe's privacy policy: https://www.adobe.com/de/privacy.html. For more information about the Adobe Typekit service, please visit: https://www.typekit.com. b. Legal basis for processing The legal basis for the integration of Typekit web fonts and the associated data transfer to Adobe is your consent (Art. 6 para. 1 lit. a GDPR). c. Data categories IP address d. Recipients Recipients of the data are internal IT and Marketing staff and Adobe as a processor. e. Storage periods Data will only be processed in this context as long as the corresponding consent has been given. After that, they will be deleted unless there are legal retention obligations to the contrary. To contact us in this context, please use the contact details provided at the beginning of this Privacy Policy. f. Legal / contractual requirement The provision of personal data is neither legally, nor contractually required, but is based on your voluntary consent. However, the correct display of the contents of standard fonts cannot be made possible without your consent. g. Third Party Transfer Adobe processes your data in the USA. To ensure the level of data protection in this third country, we have concluded standard data protection clauses with Adobe. h. Withdrawal of consent You can revoke your consent to the storage of your personal data at any time with effect for the future. i. Automated decision making and profiling As a responsible company, we do not use automated decision-making or profiling for this data processing.

Adcell

This website uses tracking cookies from Firstlead GmbH with the ADCELL brand (www.adcell.de). As soon as the visitor clicks on an advertisement with the partner link, a cookie is set. Firstlead GmbH / ADCELL uses cookies to track the origin of orders. In addition, Firstlead GmbH / ADCELL uses so-called tracking pixels. These allow information such as visitor traffic on the pages to be evaluated. The information generated by cookies and tracking pixels about the use of this website (including the IP address) and the delivery of advertising formats is transmitted to a server of Firstlead GmbH / ADCELL and stored there. Among other things, Firstlead GmbH / ADCELL can recognise that the partner link on this website has been clicked. Firstlead GmbH / ADCELL may pass this (anonymised) information on to contractual partners under certain circumstances, but data such as the IP address will not be merged with other stored data.

XXVI. Popupsmart

a. Art und Zweck der Verarbeitung Um auf unserer Website auf aktuelle Aktionen und Angebote hinzuweisen, nutzen wir Pop-Ups, also kleine Fenster, die sich im Browser automatisch öffnen. Für die Ausspielung und Erfolgsmessung der Pop-Ups nutzen wir den Service von Popupsmart, 1777 NW 72 Ave Miami, FL 33126, USA. Die Datenschutzhinweise des Anbieters können Sie unter https://popupsmart.com/privacy-policy/ einsehen. b. Rechtliche Grundlage der Verarbeitung Die Verarbeitung der übermittelten Daten erfolgt auf Grundlage Ihrer Einwilligung, um entsprechende Hinweise zu aktuellen Aktionen und Angebote darstellen zu können "Advertising" nach Art. 6 Abs. 1 lit. a) DSGVO. c. Datenkategorien IP-Adresse, Gerätedaten, Referrer, etc. d. Empfänger Empfänger der Daten sind interne Mitarbeiter der Aviteo GmbH und Popupsmart als Auftragsverarbeiter. Hierfür haben wir mit dem Anbieter den entsprechenden Auftragsverarbeitungsvertrag abgeschlossen. e. Speicherfristen Daten werden in diesem Zusammenhang nur verarbeitet, solange die entsprechende Einwilligung vorliegt. Danach werden sie gelöscht, soweit keine gesetzlichen Aufbewahrungspflichten entgegenstehen. Zur Kontaktaufnahme in diesem Zusammenhang nutzen Sie bitte die am Anfang dieser Datenschutzerklärung angegebenen Kontaktdaten. f. Gesetzliche / vertragliche Erfordernis Die Bereitstellung Ihrer personenbezogenen Daten erfolgt freiwillig, allein auf Basis Ihrer Einwilligung. Grundsätzlich kann eine betroffene Person von Ihrem Widerrufsrecht bei der Verarbeitung von personenbezogenen Daten Gebrauch machen. g. Drittstaatentransfer Die Verarbeitung erfolgt auch außerhalb der Europäischen Union (EU) oder des Europäischen Wirtschaftsraums (EWR). Um das Datenschutzniveau in diesem Drittland zu gewährleisten, haben wir mit Popupsmart die Standarddatenschutzklauseln geschlossen. h. Widerruf der Einwilligung Die Einwilligung zur Speicherung Ihrer persönlichen Daten können Sie jederzeit mit Wirkung für die Zukunft widerrufen. Sie können uns jederzeit Ihren Widerruf über die am Anfang dieser Datenschutzhinweise angegebene Kontaktmöglichkeit mitteilen. i. Automatisierte Entscheidungsfindung und Profiling Als verantwortungsbewusstes Unternehmen verzichten wir auf eine automatische Entscheidungsfindung oder ein Profiling bei dieser Datenverarbeitung.

Tiktok

a. Nature and purpose of the processing Thank you for your interest in our presence on TikTok. We would like to give you an overview of what data is collected, used and stored by us there. Social networks can usually comprehensively analyse your user behaviour when you visit their website or a website with integrated social media content (e.g. like buttons or advertising banners). Visiting our social media presence on TikTok triggers numerous data protection-related processing operations. Specifically: If you are logged into your TikTok account and visit our social media presence, TikTok may associate this visit with your user account. However, your personal data may also be collected under certain circumstances if you are not logged in or do not have an account on TikTok. In this case, this data is collected, for example, via cookies that are stored on your terminal device or by recording your IP address. With the help of the data collected in this way, TikTok can create user profiles in which your preferences and interests are stored. In this way, you can be shown interest-based advertising inside and outside TikTok. If you have an account on TikTok, interest-based advertising may be displayed on all devices on which you are or have been logged in. Please also note that we cannot track all processing on TikTok. Therefore, additional processing operations may be carried out by TikTok. For details, please refer to TikTok's terms of use and privacy policy. b. Legal basis of the processing The processing is carried out in accordance with Art. 6 para. 1 lit. f. GDPR on the basis of our legitimate interest of contacting our customers. The analysis processes initiated by TikTok may be based on different legal bases to be indicated by TikTok (e.g. consent within the meaning of Art. 6 para. 1 lit. a GDPR). c. Data categories Please refer to TikTok's privacy policy to find out which specific data is collected and how it is used: TikTok: https://www.tiktok.com/legal/privacy-policy d. Recipients Employees of your own company TikTok e. Storage periods After the end of the purpose and the end of the use of TikTok by us, the data collected in this context will be deleted. f. Legal / contractual requirement The provision of your personal data is voluntary. Without the provision of your personal data we cannot grant you access to our offered contents and services. g. Third country transfer Processing is also carried out by TikTok outside the European Union (EU) or the European Economic Area (EEA). h. Revocation of consent If your personal data is processed on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right to object to the processing of your personal data pursuant to Art. 21 GDPR, provided that there are grounds for doing so which arise from your particular situation or the objection is directed against direct marketing. If you wish to exercise your right of objection, it is sufficient to send an e-mail to the above contact address. i. Automated decision-making and profiling As a responsible company, we do not use automated decision-making or profiling for this data processing.

Alveco

Alevco is a cookie-based targeting technology of Alevco UG, Subbelrather Str. 15a, 50823 Cologne, Germany. Alevco collects pseudonymized information about users' visits and interaction with this website for advertising purposes. In no case will the pseudonymized data be used to personally identify users of this website. Users can object to the setting of cookies by Alevco at the URL https://cdn.alevco.de/opt-out.

XXIX. Retargeting TRG

Auf unserer Website werden Cookies zur Ermöglichung der Schaltung von Retargeting-Kampagnen der The Reach Group GmbH (Am Karlsbad 16, 10785 Berlin, Deutschland) eingesetzt. Bei den gespeicherten Daten innerhalb des Cookies handelt es sich nur um eine verschlüsselte, pseudonymisierte User-ID. Die eingesetzte Adserving-Technologie verwendet eine verkürzte und gehashte IP-Adressen zur Auswertung der geographischen Region, der Zugangsgeschwindigkeit sowie des Internet-Providers. Zudem werden Zeitpunkt des Besuches, die IDs der Produkte, die betrachtet, gesucht oder gekauft wurden, die URLs der betrachteten Seiten, mögliche Suchbegriffe und/oder die IDs der aufgerufenen Kategorien gespeichert, um relevantere Werbeinhalte auszuliefern. Eine Speicherung von IP- oder Browser-Daten erfolgt ausschließlich in Deutschland und zur anonymisierten Anfertigung von Besucherstatistiken und Zuordnung von Transaktionen. Ein Rückschluss auf konkreten Personen, der genauen Adresse, des Aufenthaltsortes oder weitergehenden persönlichen Daten ist dabei zu keinem Zeitpunkt möglich. Es erfolgt keine explizite Weitergabe von IP-Daten an Dritte. Alle Informationen verfügen zudem über ein Verfallsdatum von maximal 90 Tagen, ab dem Ihr Browser die gespeicherten Daten automatisch löscht. Sie können die Speicherung des Cookies durch eine entsprechende Einstellung Ihrer Browser-Software verhindern. Sie können darüber hinaus die Erfassung der durch das Cookie erzeugten und auf Ihre Nutzung der Website bezogenen Daten verhindern, indem Sie die OptOut-Funktion unter dem folgenden Link aktivieren: https://hal9000.redintelligence.net/privacy/8lcfmzhxc8d6/ Weitere Informationen zum Datenschutz der The Reach Group GmbH finden Sie unter https://trg.de/datenschutzerklarung/ Dieser Widerspruch gilt so lange, wie das zugehörige OptOut-Cookie nicht gelöscht wird. Dieses Cookie wird für die Domain, pro Browser und Benutzer eines Rechners gesetzt. Wenn Sie auf unsere Webseite von mehreren Endgeräten und Browsern aus zugreifen, müssen Sie daher auf jedem dieser Geräte und in jedem Browser der Datenerfassung separat und erneut widersprechen.

XXX. Outbrain

Outbrain bietet in seinem Publisher-Netzwerk Empfehlungen, die von einem Werbetreibenden bezahlt werden können. Wenn Sie Ihre Zustimmung erteilen, gibt Outbrain Empfehlungen basierend darauf, wie Sie mit Inhalten interagieren, auf denen Outbrain installiert ist. Diese Empfehlungen und Werbung erscheinen nur auf Outbrain-Werbeflächen, entweder auf Outbrain Engage-Werbeflächen oder im Outbrain Extended Network. Wenn Sie erfahren möchten, welche Informationen Outbrain über Ihre Interessen hat, können Sie hier Ihr Interessenprofil einsehen und Ihre Auswahl bearbeiten (wie zum Beispiel Ihr Einverständnis widerrufen). Sie können auch die Network Advertising Alliance oder YourOnlineChoices besuchen, um mehr über andere Organisationen zu erfahren, Ihre Online-Interaktionen nachverfolgen, und dort einen Opt-Out vornehmen oder Ihr Einverständnis eines solchen Trackings widerrufen. Outbrains Datenschutzbestimmungen beschreiben darüber hinaus, wie Outbrain Ihre persönlichen Informationen sammelt, nutzt und teilt. Outbrain kann einige Ihrer persönlichen Informationen an Drittunternehmen weiterleiten, um Anzeigen auszuspielen, die wahrscheinlicher Ihren Interessen entsprechen. Besuchen Sie Ihr Interessenprofil, um Ihr Einverständnis für verhaltensbezogene Anzeigen zu widerrufen und/oder die Weiterleitung Ihrer persönlichen Informationen an Drittanbieter durch Outbrain zu unterbinden. Diese Website verwendet Technologie der Outbrain Inc. (“Outbrain”, 39 W 13th Street New York, NY 10011 USA). Diese ermöglicht es, gezielt jene Internet-User mit Werbung anzusprechen, die sich bereits für unsere Angebote auf den Seiten unserer Partner interessiert haben, bzw. Daten darüber zu erheben. Die Technologie hängt von einer Cookie-basierten Analyse des Benutzerverhaltens ab. Diese Werbung erscheint nur auf Outbrain Werbeplätzen, entweder auf Werbeflächen von Outbrain Engage oder dem Outbrain Extended Network. Wenn Sie nicht möchten, dass Ihnen interessenbezogene Werbung angezeigt wird, können Sie diese Funktion hier deaktivieren. https://www.outbrain.com/legal/privacy#privacy-policy

Chatfast.io

We use the widget from Chatfast.io. When using the chatbot, a connection is established to the servers of Chatfast.io. The company assures that no personal data is used for purposes other than those listed in the privacy policy and the general terms and conditions. Personal data includes, depending on the voluntary input, name, e-mail address as well as telephone number. The legal basis for the transmission and processing of the data is based on the consent of the user (Art. 6 para. 1 lit. a GDPR). When ChatFast.io processes data, user data may be transferred and processed outside the European Economic Area (EEA), in particular the USA. In order to establish an appropriate level of data protection, we have concluded the EU standard contractual clauses with the provider. For more information on data use, please see Chatfast's privacy policy at https://www.chatfast.io/privacy-policy and the general terms and conditions at https://www.chatfast.io/terms-of-use.

XXXII. Risk.Ident

a. Art und Zweck der Verarbeitung Die von Ihnen im Rahmen einer Bestellung angegebenen Daten können dazu genutzt werden, um zu überprüfen, ob ein atypischer Bestellvorgang vorliegt (z.B. zeitgleiche Bestellung einer Vielzahl von Waren/Dienstleistungen an dieselbe Adresse unter Nutzung verschiedener Kundenkonten). An der Durchführung einer solchen Überprüfung besteht grundsätzlich ein berechtigtes Interesse. Zur Vermeidung von Betrugsfällen greifen wir beim Betrieb unserer Website außerdem auf die Dienste der Risk.Ident GmbH, Am Sandtorkai 50, 20457 Hamburg, zurück. Risk.Ident erhebt und verarbeitet mit Hilfe von Cookies und anderen Tracking-Technologien Daten zur Ermittlung des vom Nutzer verwendeten Endgeräts und weitere Daten über die Nutzung der Website. Eine Zuordnung zu einem bestimmten Nutzer erfolgt dabei nicht. Soweit durch Risk.Ident IP-Adressen erhoben werden, erfolgt eine sofortige Chiffrierung. Die Daten werden von Risk.Ident in einer Datenbank zur Betrugsprävention hinterlegt. In der Datenbank werden auch durch uns an Risk.Ident übermittelte Daten zu Endgeräten gespeichert, unter deren Verwendung es bereits zu (versuchten) Betrugstaten gekommen ist. Auch insoweit erfolgt keine Zuordnung zu bestimmten Nutzern. Im Rahmen ihrer Prüfungen rufen wir aus der Datenbank von Risk.Ident eine Risikobewertung zum Endgerät des Nutzers ab. Diese Risikobewertung zur Wahrscheinlichkeit eines Betrugsversuchs berücksichtigt u.a., ob das Endgerät sich über verschiedene Service-Provider eingewählt hat, ob das Endgerät eine häufig wechselnde Geo-Referenz aufweist, wie viele Transaktionen über das Endgerät getätigt wurden und ob eine Proxy-Verbindung genutzt wird. b. Rechtliche Grundlage der Verarbeitung Die Verarbeitung der übermittelten Daten erfolgt auf Grundlage unserer berechtigten Interessen zur Betrugsverhinderung (Art. 6 Abs. 1 lit. f DSGVO). c. Datenkategorien IP-Adresse, verwendeter Browser, Zeitstempel, etc. d. Empfänger Empfänger der Daten sind interne Mitarbeiter der Aviteo und Risk.Ident als Auftragsverarbeiter. Hierfür haben wir mit Risk.Ident den entsprechenden Auftragsverarbeitungsvertrag abgeschlossen. e. Speicherfristen Daten werden in diesem Zusammenhang nur 14 Tage verarbeitet. Danach werden sie gelöscht, soweit keine gesetzlichen Aufbewahrungspflichten entgegenstehen. Zur Kontaktaufnahme in diesem Zusammenhang nutzen Sie bitte die am Anfang dieser Datenschutzerklärung angegebenen Kontaktdaten. f. Gesetzliche / vertragliche Erfordernis Grundsätzlich kann eine betroffene Person von keinem Widerspruchsrecht bei der Verarbeitung von personenbezogenen Daten im Zusammenhang einer Betrugsverhinderung gebrauch machen. g. Drittstaatentransfer Die Verarbeitung erfolgt ausschließlich in der Europäischen Union (EU) oder des Europäischen Wirtschaftsraums (EWR). h. Profiling Es findet kein Profiling statt.

Matomo Analytics

This website uses Matomo, a web analytics service. Matomo is software developed by InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand. Matomo is used as an on-premise solution and is operated in compliance with the GDPR. Matomo uses “cookies,” which are text files stored on your computer. These cookies help us track your actions on this website, assisting us in continuously improving it. The information is stored on a server managed by us, located within the European Union. IP anonymization is enabled, and your IP address is shortened. The generated information about website usage is not shared with third parties. You can prevent cookies from being installed by adjusting your browser settings; however, please note that doing so may limit the full functionality of this website. You can object to the storage and use of your data at any time with a single click. In this case, an opt-out cookie will be stored in your browser, meaning Matomo will not collect session data. Important: If you delete your cookies, the opt-out cookie will also be deleted and must be reactivated. Below, you can check your current settings for this website. You can object to the storage of data at any time. If the checkbox is selected, data about your visit will be stored in Matomo. You can uncheck the box to prevent further recordings. Matomo Opt-Out

Youform

We use the service Youform, provided by Youform, to collect feedback. Youform allows users to easily submit feedback via online forms. The data you enter is transmitted directly to Youform and processed there. The use of Youform is based on our legitimate interest in providing an efficient and user-friendly way to collect feedback in accordance with Art. 6 (1) lit. f GDPR. For more information on how Youform processes personal data, please refer to the Youform Privacy Policy. https://youform.com/privacy-policy/