Privacy policy

<h1>Data Policy</h1> <h2>1) Information about the collection of personal data and contact details of the controller</h2> <p><b>1.1</b> We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data includes all data with which you can be personally identified.</p> <p><b>1.2</b> The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Nebelin GbR, Auf der oberen Au 43a, 77797 Ohlsbach, Germany. The controller for the processing of personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.</p> <p><b>1.3</b> For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser line.</p> <h2>2) Data collection when visiting our website</h2> <p>When using our website for informational purposes only, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser sends to our server (so-called "server log files"). When you visit our website, we collect the following data, which is technically necessary for us to display the website:</p> <ul> <li>Our visited website</li> <li>Date and time of access</li> <li>Amount of data sent in bytes</li> <li>Source/reference from which you accessed the page</li> <li>Used browser</li> <li>Operating system used</li> <li>IP address used (if applicable, in anonymized form)</li> </ul> <p>Processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. There is no further disclosure or use of the data. However, we reserve the right to retrospectively check the server log files should concrete indications point to unlawful use.</p> <h2>3) Hosting & Content Delivery Network</h2> <p><b>Hosting by Shopify</b><br> We use the shop system of the service provider Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify") for the purpose of hosting and displaying the online shop based on processing on our behalf. All data collected on our website is processed on Shopify's servers. As part of the services provided by Shopify, data may also be transmitted to Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada, Shopify Data Processing (USA) Inc., Shopify Payments (USA) Inc., or Shopify (USA) Inc. For the transfer of data to Shopify Inc. in Canada, the adequacy decision of the European Commission ensures the appropriate level of data protection. Further information on Shopify's privacy policy can be found on the following website: <a href="https://www.shopify.de/legal/datenschutz" target="_blank">https://www.shopify.de/legal/datenschutz</a><br> Processing on other servers than the aforementioned Shopify servers only takes place within the scope communicated below.</p> <h2>4) Cookies</h2> <p>To make your visit to our website attractive and to enable the use of certain functions, we use cookies, small text files that are stored on your device. Some of these cookies are automatically deleted after you close your browser (so-called "session cookies"), while others remain on your device and allow us to save your settings for future visits (so-called "persistent cookies"). In the latter case, you can find the storage duration in the cookie settings of your web browser.<br> If personal data is also processed by individual cookies set by us, the processing is carried out in accordance with Art. 6 Para. 1 lit. b GDPR either for the execution of the contract, in accordance with Art. 6 Para. 1 lit. a GDPR in the case of consent given, or in accordance with Art. 6 Para. 1 lit. f GDPR to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the page visit.<br> You can set your browser so that you are informed about the setting of cookies and individually decide on their acceptance or exclude the acceptance of cookies for certain cases or in general.<br> Please note that if you do not accept cookies, the functionality of our website may be limited.</p> <h2>5) Contact</h2> <p>When contacting us (e.g., via contact form or email), personal data is processed exclusively for the purpose of handling and responding to your request, and only to the extent necessary for this purpose. The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Art. 6 Para. 1 lit. f GDPR. If your contact is aimed at concluding a contract, an additional legal basis for processing is Art. 6 Para. 1 lit. b GDPR. Your data will be deleted when it can be inferred from the circumstances that the relevant matter has been finally clarified and there are no legal retention obligations.</p> <h2>6) Comment Function</h2> <p>As part of the comment function on this website, in addition to your comment, information on the time the comment was created and the commentator name chosen by you are stored and published on the website. Furthermore, your IP address is stored for security reasons and in the event that the person concerned violates the rights of third parties or posts illegal content by submitting a comment. We need your email address to contact you if a third party should object to your published content as unlawful. The legal basis for the storage of your data is Art. 6 Para. 1 lit. b and f GDPR. We reserve the right to delete comments if they are objected to as unlawful by third parties.</p> <h2>7) Use of your data for direct advertising</h2> <p><b>7.1</b> Registration for our email newsletter<br> If you register for our email newsletter, we will send you regular information about our offers. The only mandatory information for sending the newsletter is your email address. The provision of further data is voluntary and is used to address you personally. We use the so-called double opt-in procedure for sending the newsletter. This means that we will not send you an email newsletter until you have expressly confirmed to us that you agree to the sending of the newsletter. We will then send you a confirmation email asking you to confirm that you wish to receive future newsletters by clicking on an appropriate link.</p> <p><b>7.2</b> Sending of the email newsletter to existing customers<br> If you have provided us with your email address when purchasing goods or services, we reserve the right to regularly send you offers for goods or services from our range that are similar to those you have already purchased, based on our legitimate interests. You do not need to provide any separate consent for this. In this respect, data processing is carried out solely on the basis of our legitimate interest in personalized direct mail in accordance with Art. 6 Para. 1 lit. f GDPR. If you have initially objected to the use of your email address for this purpose, we will not send you a mail. You are entitled to object to the use of your email address for the aforementioned advertising purpose at any time with effect for the future by notifying the controller named at the beginning. In this regard, you only have to pay transmission costs according to the basic rates. Upon receipt of your objection, the use of your email address for advertising purposes will cease immediately.</p>

<h2>8) Site Functionalities</h2>

<p><b>8.1</b> Usage of YouTube Videos<br>
This website utilizes the YouTube embedding feature to display and play videos from the provider "YouTube," which belongs to Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").<br>
The extended privacy mode is used, which, according to the provider, initiates the storage of user information only upon video playback. When playing embedded YouTube videos, the provider "YouTube" uses cookies to collect information about user behavior. According to "YouTube," these cookies are used to capture video statistics, improve user-friendliness, and prevent abusive actions. If you are logged into Google, your data will be directly associated with your account when you click on a video. If you do not wish to associate it with your YouTube profile, you must log out before activating the button. You have the right to object to the creation of these user profiles, and to exercise this right, you must contact YouTube. During the use of YouTube, personal data may be transmitted to the servers of Google LLC. in the USA.<br>
Regardless of playing embedded videos, accessing this website establishes a connection to the Google network, which may trigger additional data processing operations beyond our control.<br>
All the described processes, especially the extraction of information from the used device through the tracking pixel, are only carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, the use of YouTube videos during your site visit will be omitted.<br>
You can revoke your given consent at any time with effect for the future. To exercise your revocation, please deactivate this service using the "Cookie Consent Tool" provided on the website or through alternative options communicated on the website.<br>
For more information on data protection at "YouTube," refer to the YouTube Terms of Service at <a href="https://www.youtube.com/static?template=terms" target="_blank">https://www.youtube.com/static?template=terms</a> and Google's Privacy Policy at <a href="https://www.google.de/intl/de/policies/privacy" target="_blank">https://www.google.de/intl/de/policies/privacy</a></p>

<p><b>8.2</b> - Google Web Fonts<br>
This site uses web fonts provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google") for the consistent display of fonts. When a page is loaded, your browser downloads the required web fonts into its browser cache to display text and fonts correctly.<br>
For this purpose, the browser you are using must establish a connection to Google's servers. This may also involve the transmission of personal data to the servers of Google LLC. in the USA. This way, Google becomes aware that our website has been accessed via your IP address. The processing of personal data in the context of connecting to the font provider is only carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service using the "Cookie Consent Tool" provided on the website. If your browser does not support web fonts, a default font will be used from your computer.<br>
For more information on Google Web Fonts, visit <a href="https://developers.google.com/fonts/faq" target="_blank">https://developers.google.com/fonts/faq</a> and Google's Privacy Policy: <a href="https://www.google.com/policies/privacy/" target="_blank">https://www.google.com/policies/privacy/</a></p>

<p><b>8.3</b> Google reCAPTCHA<br>
This website uses the reCAPTCHA function of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). This function is primarily used to distinguish whether an input is made by a natural person or is abusive through machine and automated processing. The service includes the transmission of the IP address and, if necessary, other data required by Google for the reCAPTCHA service, and is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in determining individual responsibility on the Internet and preventing misuse and spam. In the use of Google reCAPTCHA, personal data may also be transmitted to the servers of Google LLC. in the USA.<br>
You can view further information on Google reCAPTCHA and Google's privacy policy at: <a href="https://www.google.com/intl/de/policies/privacy/" target="_blank">https://www.google.com/intl/de/policies/privacy/</a><br>
To the extent legally required, we have obtained your consent in accordance with Art. 6 para. 1 lit. a GDPR for the processing of your data as described above. You can revoke your given consent at any time with effect for the future. To exercise your revocation, please follow the above-mentioned option to object.<br>
For the transfer of data from the EU to the USA, Google relies on the so-called Standard Data Protection Clauses of the European Commission, which are intended to ensure compliance with the European data protection level in the USA.</p>

<h2>9) Tools and Miscellaneous</h2>

<p><b>9.1</b> - Lexoffice<br>
For accounting purposes, we use the service of the cloud-based accounting software "lexoffice" provided by Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg.<br>
Lexoffice processes incoming and outgoing invoices and possibly also the bank transactions of our company to automatically record invoices, match transactions, and create financial accounting in a partially automated process.<br>
If personal data is processed in this context, the processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in efficient organization and documentation of our business transactions.<br>
For more information on lexoffice, automated data processing, and data protection regulations, visit <a href="https://www.lexoffice.de/datenschutz/" target="_blank">https://www.lexoffice.de/datenschutz/</a></p>

<p><b>9.2</b> Cookie Consent Tool</p>

<p>This website uses a "Cookie Consent Tool" to obtain effective user consent for consent-required cookies and cookie-based applications. The "Cookie Consent Tool" is displayed to users as an interactive user interface when the page is accessed, allowing consent for specific cookies and/or cookie-based applications through checkbox selection. With the use of the tool, all consent-required cookies/services are only loaded if the respective user grants consent by checking the boxes. This ensures that such cookies are only set on the user's device in the case of granted consent.<br>
The tool sets technically necessary cookies to store your cookie preferences. Personal user data is generally not processed in this process.<br>
In individual cases, for the purpose of storing, assigning, or logging cookie settings, the processing of personal data (such as the IP address) may occur, and this is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in a legally compliant, user-specific, and user-friendly consent management for cookies and thus a legally compliant design of our online presence.<br>
Another legal basis for processing is Art. 6 para. 1 lit. c GDPR. As responsible parties, we are subject to the legal obligation to make the use of technically unnecessary cookies dependent on the respective user's consent.<br>
For more information on the operator and the settings of the Cookie Consent Tool, please refer directly to the corresponding user interface on our website.</p>

<h2>10) Rights of the Data Subject</h2>

<p><b>10.1</b> The applicable data protection law grants you the following rights regarding the processing of your personal data by the data controller (information and intervention rights), with reference to the specified legal basis for the respective exercise conditions:</p>

<ul>
<li>Right to information according to Art. 15 GDPR;</li>
<li>Right to rectification according to Art. 16 GDPR;</li>
<li>Right to erasure according to Art. 17 GDPR;</li>
<li>Right to restriction of processing according to Art. 18 GDPR;</li>
<li>Right to information according to Art. 19 GDPR;</li>
<li>Right to data portability according to Art. 20 GDPR;</li>
<li>Right to withdraw consent granted according to Art. 7 para. 3 GDPR;</li>
<li>Right to lodge a complaint according to Art. 77 GDPR.</li>
</ul>

<p><b>10.2</b> RIGHT TO OBJECT</p>

<p>If, within the framework of a balancing of interests, we process your personal data based on our overriding legitimate interest, you have the right to object at any time, for reasons arising from your particular situation, to this processing with future effect.<br>
If you make use of your right to object, we will cease processing the data concerned. However, further processing is reserved if we can demonstrate compelling legitimate grounds for the processing that override your interests, fundamental rights, and freedoms, or if the processing serves the assertion, exercise, or defense of legal claims.<br>
If your personal data is processed by us for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising. You can exercise the objection as described above.<br>
If you make use of your right to object, we will cease processing the data concerned for direct marketing purposes.</p>

<h2>11) Duration of Storage of Personal Data</h2>

<p>The duration of the storage of personal data is determined by the respective legal basis, the purpose of processing, and, if applicable, additionally by the respective statutory retention period (e.g., commercial and tax retention periods).</p>

<p>For processing personal data based on explicit consent according to Art. 6 para. 1 lit. a GDPR, this data will be stored until the data subject revokes their consent.</p>

<p>If there are statutory retention periods for data processed within the scope of contractual or quasi-contractual obligations based on Art. 6 para. 1 lit. b GDPR, these data will be routinely deleted after the retention periods expire, provided they are no longer required for contract fulfillment or initiation, and there is no longer a legitimate interest on our part in continued storage.</p>

<p>For processing personal data based on Art. 6 para. 1 lit. f GDPR, this data will be stored until the data subject exercises their right to object according to Art. 21 para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject, or the processing serves the assertion, exercise, or defense of legal claims.</p>

<p>For processing personal data for the purpose of direct advertising based on Art. 6 para. 1 lit. f GDPR, this data will be stored until the data subject exercises their right to object according to Art. 21 para. 2 GDPR.</p>

<p>Unless otherwise indicated in the specific processing situations described in this statement, stored personal data will be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.</p>