Privacy Policy of Datashop24.com
1. Data Protection at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit our website.
Personal data refers to any data that can be used to personally identify you.
Detailed information on data protection can be found in our privacy policy below.
Data Collection on Our Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator.
You can find the operator’s contact details in the website’s legal notice (Impressum).
How do we collect your data?
Some data is collected when you provide it to us. This may include data you enter into a contact form, for example.
Other data is automatically collected by our IT systems when you visit the website. This primarily includes technical data (e.g. web browser, operating system, or time of page access). This data is collected automatically as soon as you enter our website.
What Do We Use Your Data For?
Part of the data is collected to ensure the website is provided without errors.
Other data may be used to analyze your user behavior.
What Rights Do You Have Regarding Your Data?
You have the right to obtain, at any time and free of charge, information about the origin, recipient, and purpose of your stored personal data.
You also have the right to request the correction, blocking, or deletion of this data.
For this purpose and for any other questions concerning data protection, you can contact us at any time via the address provided in the legal notice.
You also have the right to lodge a complaint with the relevant supervisory authority.
A list of supervisory authorities (for non-public entities) and their contact information can be found at:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html
In addition, you have the right, under certain circumstances, to request the restriction of the processing of your personal data.
Details can be found in this privacy policy under “Right to Restriction of Processing”.
Analytics and Third-Party Tools
When visiting our website, your browsing behavior may be statistically evaluated.
This is mainly done using cookies and analytics programs.
The analysis of your browsing behavior is usually anonymous; the behavior cannot be traced back to you.
You can object to this analysis or prevent it by not using certain tools.
Detailed information can be found in the following privacy policy.
You have the right to object to this analysis. We will inform you about your options to object in this privacy policy.
2. General Information and Mandatory Disclosures
Data Protection
The operators of this website take the protection of your personal data very seriously.
We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
When you use this website, various personal data is collected.
Personal data refers to data that can be used to personally identify you.
This privacy policy explains what data we collect and what we use it for.
It also explains how and for what purpose this is done.
Please note that data transmission over the Internet (e.g., when communicating via email) may have security vulnerabilities.
Complete protection of data from access by third parties is not possible.
Information About the Data Controller
The data controller responsible for processing data on this website is:
Pumox GmbH
John-F.-Kennedy-Str. 5
34128 Kassel
Germany
Phone: +49 561 47395330
Email: [email protected]
The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data (e.g., names, email addresses, etc.).
Revocation of Your Consent to Data Processing
Many data processing operations are only possible with your explicit consent.
You may revoke your consent at any time by sending us an informal email.
The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to Object to Data Processing in Special Cases and to Direct Marketing (Art. 21 GDPR)
If data processing is carried out on the basis of Art. 6(1)(e) or (f) GDPR, you have the right, at any time and for reasons arising from your particular situation, to object to the processing of your personal data, including profiling based on those provisions.
The relevant legal basis for processing can be found in this privacy policy.
If you object, we will no longer process your affected personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing is necessary for the establishment, exercise, or defense of legal claims (objection under Art. 21(1) GDPR).
If your personal data is processed for direct marketing purposes, you have the right to object at any time to such processing, including profiling related to direct marketing.
If you object, your personal data will no longer be used for these purposes (objection under Art. 21(2) GDPR).
Right to Lodge a Complaint with a Supervisory Authority
In case of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR in conjunction with § 19 BDSG), particularly in the member state of their habitual residence, place of work, or the location of the alleged violation.
This right exists without prejudice to any other administrative or judicial remedies.
A list of supervisory authorities (for non-public entities) and their contact information can be found at:
https://www.bfdi.bund.de/DE/Service/Anschriften/anschriften_table.html
Right to Data Portability
You have the right to receive data that we process based on your consent or in fulfillment of a contract in a commonly used, machine-readable format.
You may also request the transfer of this data to another controller, where technically feasible.
SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content—such as orders or inquiries sent to us as the site operator—this site uses SSL or TLS encryption.
You can recognize an encrypted connection by the change in the browser’s address line from “http://” to “https://” and by the padlock symbol in your browser bar.
When SSL or TLS encryption is activated, data you transmit to us cannot be read by third parties.
Encrypted Payment Transactions on This Website
If there is a requirement to transmit your payment data (e.g., account number for direct debit) after concluding a paid contract, this data is needed to process the payment.
Payment transactions using common methods (e.g., Visa/MasterCard, direct debit) are processed exclusively via an encrypted SSL or TLS connection.
You can recognize an encrypted connection by the change in the browser’s address line from “http://” to “https://” and by the padlock symbol in your browser bar.
When communication is encrypted, your payment data cannot be read by third parties.
Right to Access, Blocking, Deletion, and Correction
Within the scope of the applicable legal provisions, you have the right to receive free information at any time about your stored personal data, its origin and recipient, and the purpose of data processing.
You also have the right to request correction, blocking, or deletion of this data.
For further questions on personal data, you can contact us at any time using the address provided in the legal notice.
Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data.
You may contact us at any time using the address provided in the legal notice.
The right to restriction applies in the following cases:
- If you contest the accuracy of your personal data stored by us, we usually need time to verify this.
For the duration of the verification, you have the right to request the restriction of processing. - If the processing of your personal data was/is unlawful, you may request the restriction of processing instead of deletion.
- If we no longer need your personal data, but you require it for the establishment, exercise, or defense of legal claims, you may request the restriction of processing instead of deletion.
- If you have objected pursuant to Art. 21(1) GDPR, a balance must be struck between your interests and ours.
Until it is determined whose interests prevail, you have the right to request the restriction of processing of your personal data.
If you have restricted the processing of your personal data, such data—apart from being stored—may only be processed with your consent, or for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.
Objection to Promotional Emails
The use of contact information published under the legal notice obligation for sending unsolicited advertising and informational material is hereby expressly prohibited.
The operators of this website reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam emails.
3. Data Protection Officer
Legally Required Data Protection Officer
We have appointed a data protection officer for our company:
Jacek Gehrke
John-F.-Kennedy-Str. 5
34128 Kassel
Germany
Phone: +49 561 47395330
Email: [email protected]
4. Data Collection on Our Website
Cookies
Our websites use what are known as cookies. Cookies do not harm your device and do not contain viruses. They are used to make our services more user-friendly, efficient, and secure. Cookies are small text files that are stored on your device by your browser.
Most of the cookies we use are known as “session cookies.” They are automatically deleted after your visit ends. Other cookies remain stored on your device until you delete them. These cookies enable us to recognize your browser on your next visit.
You can configure your browser to inform you about the use of cookies and to allow cookies only in individual cases, to accept cookies in specific cases or generally exclude them, and to automatically delete cookies when the browser is closed. Disabling cookies may limit the functionality of this website.
Cookies required for the performance of electronic communication or the provision of certain functions you request (e.g., shopping cart) are stored based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in storing cookies for the technically error-free and optimized delivery of services. Any other cookies (e.g., for analyzing user behavior) are covered separately in this privacy policy.
Server Log Files
The provider of the website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These may include:
- Browser resolution, type, and version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
- Language setting
Google Analytics and Microsoft Clarity have access to user IP addresses. These are used to analyze behavior, identify errors encountered by users, and improve the website.
The user’s country and region are determined using the IP address and browser language. Based on this information, the content of product pages is automatically adjusted.
This data is not automatically deleted.
This data will not be combined with other data sources.
The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of the website — for this purpose, server log files must be collected.
Providing the above-mentioned personal data is neither legally nor contractually required. However, without the IP address, the functionality of the website cannot be guaranteed.
Contact Form
If you send us inquiries via the contact form, the information you provide — including your contact details — will be stored by us for the purpose of processing your request and in case of follow-up questions. We do not share this data without your consent.
The processing of the data entered into the contact form is based exclusively on your consent (Art. 6(1)(a) GDPR). You may revoke your consent at any time with effect for the future by sending us an informal email. The legality of the data processing carried out prior to the revocation remains unaffected.
The data you enter in the contact form will be stored until you request deletion, revoke your consent, or the purpose for data storage no longer applies (e.g., once your inquiry has been fully handled). Mandatory legal provisions — in particular retention periods — remain unaffected. Providing your personal data is voluntary. However, we can only process your request if you provide your name, email address, and reason for the inquiry.
Inquiries by Email, Phone, or Fax
If you contact us by email, telephone, or fax, your inquiry, including all resulting personal data (name, nature of inquiry), will be stored and processed by us for the purpose of handling your request. We do not share this data without your consent.
The processing of this data is based on Art. 6(1)(b) GDPR, if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on your consent (Art. 6(1)(a) GDPR) and/or on our legitimate interests (Art. 6(1)(f) GDPR), since we have a legitimate interest in the effective processing of inquiries directed to us.
The data sent to us via contact inquiries will remain with us until you request deletion, revoke your consent to storage, or the purpose for data retention no longer applies (e.g., after your inquiry has been resolved). Mandatory legal requirements — particularly retention obligations — remain unaffected.
Registration on This Website
You can register on our website to access additional features. The data entered during registration will be used solely for the purpose of using the respective service or offer. All required fields must be filled in completely; otherwise, registration cannot be completed.
For important changes — for example, in the scope of services or technically necessary updates — we may use the email address provided during registration to inform you.
The processing of registration data is based on your consent (Art. 6(1)(a) GDPR). You may revoke your consent at any time by sending us an informal email. The legality of the data processing already carried out remains unaffected by the revocation.
The data collected during registration will be stored as long as you are registered on our website and will be deleted thereafter. Legal retention periods remain unaffected.
Data Transmission for Contract Fulfillment in Online Shops, Retail, and Shipping
We transmit personal data to third parties only when necessary in the context of contract execution — for example, to companies tasked with delivering goods or the financial institution responsible for payment processing. No further transmission of your data will occur unless you have expressly consented to it. Your data will not be shared for advertising purposes without your explicit consent.
The basis for data processing is Art. 6(1)(b) GDPR, which permits data processing for the fulfillment of a contract or pre-contractual measures.
5. Analytics Tools and Advertising
Google Analytics
This website uses features of the web analytics service Google Analytics. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Analytics uses so-called “cookies” — text files that are stored on your computer and enable an analysis of your website usage. The information generated by the cookie about your use of this website is generally transmitted to a Google server in the USA and stored there.
The use of Google Analytics cookies and this analytics tool is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both the website and its advertising.
IP Anonymization
We have activated IP anonymization on this website. This means that your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before transmission to the USA. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. On behalf of the website operator, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide other services related to website and internet usage. The IP address transmitted by your browser in connection with Google Analytics will not be merged with other data held by Google.
Browser Plugin
You can prevent the storage of cookies by adjusting your browser settings; however, please note that doing so may result in some functions of this website not working properly.
Additionally, you can prevent the collection of data generated by the cookie and related to your website use (including your IP address) by Google, and the processing of this data by Google, by downloading and installing the browser plugin available at:
https://tools.google.com/dlpage/gaoptout?hl=en
Objection to Data Collection
You can prevent the collection of your data by Google Analytics by clicking the following link. This sets an opt-out cookie, which prevents your data from being collected on future visits to this website:
Disable Google Analytics
More information about how Google Analytics handles user data can be found in Google’s privacy policy:
https://support.google.com/analytics/answer/6004245?hl=en
Data Processing Agreement
We have entered into a data processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Demographic Data with Google Analytics
This website uses the “demographics” feature of Google Analytics. This allows reports to be generated containing information about the age, gender, and interests of site visitors. These data are obtained from interest-based advertising by Google and from visitor data from third-party providers. They cannot be associated with any specific individual.
You can disable this feature in your Google account ad settings or generally prohibit the collection of your data by Google Analytics as described above.
Google Analytics Remarketing
This website uses the features of Google Analytics Remarketing in conjunction with the cross-device functions of Google Ads and Google DoubleClick. Provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
This feature allows advertising audiences created with Google Analytics Remarketing to be linked with the cross-device capabilities of Google Ads and Google DoubleClick. This means that interest-based, personalized advertising messages adapted to your previous usage and browsing behavior on one device (e.g., smartphone) can also be displayed on another device (e.g., tablet or PC).
If you have given the corresponding consent, Google links your web and app browsing history with your Google account for this purpose. This enables the same personalized advertising messages to be shown on any device you sign in to with your Google account.
To support this feature, Google Analytics collects Google-authenticated user IDs, which are temporarily linked with our Google Analytics data to define and create audiences for cross-device advertising.
You can permanently opt out of cross-device remarketing/targeting by deactivating personalized ads in your Google account settings:
https://www.google.com/settings/ads/onweb/
The aggregation of collected data in your Google account is based solely on your consent (Art. 6(1)(a) GDPR), which you can grant or withdraw from Google.
For data collection processes not merged with your Google account (e.g., if you don’t have a Google account or have objected to such merging), the processing is based on Art. 6(1)(f) GDPR. The legitimate interest arises from the website operator’s desire to conduct anonymous analysis of website visitors for advertising purposes.
More information and Google’s privacy policy can be found at:
https://policies.google.com/technologies/ads?hl=en
Google Ads and Google Conversion Tracking
This website uses Google Ads. Ads is an online advertising program provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
As part of Google Ads, we use conversion tracking. When you click on an ad placed by Google, a cookie is set for conversion tracking. These cookies are small text files stored by your browser. They expire after 30 days and are not used to personally identify users. If a user visits certain pages of this website and the cookie is still valid, Google and we can recognize that the user clicked the ad and was redirected to that page.
Each Google Ads customer receives a different cookie. Cookies cannot be tracked across websites of different Ads customers. The information collected using the conversion cookie is used to compile conversion statistics for Ads customers who have opted in to conversion tracking. Customers learn the total number of users who clicked on their ad and were redirected to a page tagged for conversion tracking. However, they do not receive information that personally identifies users.
If you do not want to participate in tracking, you can opt out by disabling the Google Conversion Tracking cookie in your browser settings. You will then not be included in the conversion tracking statistics.
The storage of “conversion cookies” and the use of this tracking tool are based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in analyzing user behavior to optimize both the website and advertising.
More information about Google Ads and Google Conversion Tracking can be found in Google’s privacy policy:
https://policies.google.com/privacy?hl=en
You can configure your browser to notify you about cookies and only allow them in individual cases, accept cookies for certain cases or generally exclude them, and enable the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.
Microsoft Clarity
We use the web analytics software Microsoft Clarity on our website. The service provider is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.
Microsoft may process your data, including in the USA. Clarity/Microsoft is an active participant in the EU–US Data Privacy Framework, which ensures proper and secure data transfer of EU citizens’ personal data to the USA.
More information can be found here:
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en
In addition, Microsoft uses Standard Contractual Clauses (Art. 46(2) and (3) GDPR). These are EU Commission-approved templates designed to ensure that your data complies with European data protection standards even when transferred to third countries (such as the USA).
Through both the Data Privacy Framework and Standard Contractual Clauses, Microsoft commits to maintaining EU-level data protection even when storing, processing, or managing your data in the USA.
You can find more about Microsoft’s Standard Contractual Clauses here:
https://learn.microsoft.com/en-us/compliance/regulatory/offering-eu-model-clauses
6. Plugins and Tools
Google Web Fonts
This site uses web fonts provided by Google for consistent font display. The Google Fonts are locally installed, and no connection to Google’s servers is established in this process.
Google reCAPTCHA
We use “Google reCAPTCHA” (hereinafter “reCAPTCHA”) on our websites. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
The purpose of reCAPTCHA is to check whether data entered on our websites (e.g., in a contact form) is submitted by a human or by an automated program. reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the visitor accesses the website. During the analysis, reCAPTCHA evaluates various information (e.g., IP address, time spent on the site, or mouse movements). The data collected during the analysis is transmitted to Google.
The reCAPTCHA analyses run entirely in the background. Visitors are not notified that analysis is taking place.
Data processing is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated access and spam.
Further information about Google reCAPTCHA and Google’s privacy policy can be found at:
https://policies.google.com/privacy?hl=en
https://www.google.com/recaptcha/intro/android.html
7. Orders in the Webshop
The following information concerns the handling of your data in connection with placing an order in the webshop on our website.
User Account
When placing an order, you may create a user account. The data you provide will be used solely for the use of the offered service. Data provided during registration will not be shared with third parties unless an order is placed simultaneously. User account data is not automatically deleted.
The following data is stored during registration:
- Your IP address
- Date and time of registration
- Your name
- Your address
- Your email address
- Telephone number
By registering, you can place future orders without having to re-enter your data. The legal basis for storing this data is Art. 6(1)(b) GDPR (contract performance or pre-contractual measures).
Providing personal data is neither legally nor contractually required.
Order Processing
When you place an order through our website, we use the data you provide to process the order and fulfill our contractual obligations. The following data is stored as part of the order process:
- Your IP address
- Date and time of registration
- Your name
- Your address
- Your email address
- Telephone number
The legal basis for data processing is Art. 6(1)(b) GDPR (contract fulfillment).
Payment Processing
We store the payment method provided only when you choose bank transfer.
Depending on the payment method, your data may be forwarded to the corresponding payment service provider.
PayPal (PayPal, credit card, SEPA direct debit)
Payments are processed via PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. You do not need a PayPal account to use their services.
Alongside payment data (e.g., bank account or credit card), PayPal also processes the following data:
- Your name
- Your address
- Your email address
- IP address
These data are not shared with any third party not involved in contract fulfillment or payment processing.
Please note: PayPal may share your data with credit agencies, as outlined in their privacy policy:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=en_EN
Legal basis: Art. 6(1)(b) GDPR
PayStripe (GiroPay & Sofortüberweisung via Stripe)
We also offer payment via Stripe (℅ Legal Process, 510 Townsend St., San Francisco, CA 94103). This serves our legitimate interest in offering a secure, efficient payment method (Art. 6(1)(f) GDPR). For contract fulfillment, the following data may be shared with Stripe (Art. 6(1)(b) GDPR):
- Your name
- Your address
- Your email address
- IP address
- Bank details
- Transaction date and time
- Transaction amount
- Merchant name
Processing this data is not legally or contractually required. Without it, Stripe payments cannot be completed.
Stripe acts as both controller (for legal obligations) and processor (under our instructions, Art. 28 GDPR). Stripe has implemented Standard Contractual Clauses (SCCs) for international data transfers to ensure EU-compliant processing, even when data is stored in the USA.
Details on Stripe’s privacy policy and opt-out options can be found here:
https://stripe.com/de/privacy
Legal basis: Art. 6(1)(b) GDPR
8. Newsletter
We offer a newsletter service to inform subscribers about our services (“newsletter subscription”). To receive the newsletter, you must register on our website. The data you provide during the registration process is transmitted to us and used solely for the purpose of sending the newsletter.
This includes:
- The email address you provided
- The IP address of the computer system you used
- The date and time of registration
We require your email address to deliver the newsletter. The other data is used to help prevent abuse of our service and of the provided email address.
Providing your personal data is voluntary and is based solely on your consent or our legitimate interest. Without your consent or a legitimate interest, we are unfortunately unable to send you our newsletter.
Any additional information you provide is optional and helps us tailor the newsletter content to better match your interests. These details are not required to receive the newsletter.
Newsletter Delivery via MailChimp and AWS
We use MailChimp, a service provided by The Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA, and Amazon Web Services (AWS), provided by Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA, to send our newsletters.
The data listed above is transferred to these service providers as part of data processing under Art. 28(3)(1) GDPR. These companies do not use the data to contact you directly, nor do they share your data with third parties.
Both providers are certified under the EU–U.S. Privacy Shield framework.
Newsletter Analytics
We analyze user engagement with our newsletter emails and collect statistics such as open rates and click rates. This behavior may be linked to individual recipients.
This allows us to optimize the newsletter and better tailor it to the interests of our subscribers.
Legal Basis and Consent
Before submitting your registration for the newsletter, we will obtain your explicit consent and inform you of this privacy policy (Art. 6(1)(a) GDPR).
Right to Withdraw & Unsubscribe
You can unsubscribe from the newsletter and thus revoke your consent or object to further data processing at any time.
Each newsletter email contains a link that allows you to unsubscribe.
Until such an objection is made, we will continue to process your data for this purpose.
9. Social Plugins
We use so-called social plugins that allow you to share content on various platforms or display content from those platforms directly on our website.
If you are a member of any of these platforms, the platform operator may associate the access to content or functions with your user profile.
You can find details about the purpose and scope of data collection and further processing by the respective platform operators in their privacy policies.
Operated by: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Privacy policy: https://www.facebook.com/about/privacy/
Opt-out options:
Operated by: Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland
Privacy policy: https://twitter.com/en/privacy
Opt-out: https://optout.aboutads.info
Operated by: Pinterest Inc., 651 Brannan Street, San Francisco, CA 94103, USA
Privacy policy: https://policy.pinterest.com/en/privacy-policy
Opt-out: https://www.youronlinechoices.com
Operated by: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
Privacy policy: https://www.linkedin.com/legal/privacy-policy
Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
Data processing is based on our legitimate interest in optimizing our services and products in accordance with Art. 6(1)(f) GDPR.