Privacy policy

1) Introduction and Contact Information of the Data Controller

1.1 We are pleased that you are visiting our website and thank you for your interest. Below we inform you about the handling of your personal data when using our website. Personal data includes all data that can personally identify you.

1.2 The data controller responsible for processing on this website, within the meaning of the General Data Protection Regulation (GDPR), is Recada GmbH, Am Technologiezentrum 5, 86159 Augsburg, Germany, Tel.: 017625532157, Email: dk@recada.de. The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.

2) Data Collection When Visiting Our Website

When you use our website purely for informational purposes, i.e., if you do not register or otherwise transmit information to us, we only collect data that your browser transmits to our server (so-called "server log files"). When you visit our website, we collect the following data, which is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time at the time of access
  • Amount of data sent in bytes
  • Source/reference from which you came to the page
  • Browser used
  • Operating system used
  • IP address used (if applicable: in anonymized form)

The processing is carried out in accordance with Art. 6(1) lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be transferred or used in any other way. However, we reserve the right to retrospectively check the server log files if there are concrete indications of unlawful use.

3) Hosting & Content Delivery Network

Shopify

For hosting our website and displaying the site content, we use the system of the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify")

Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada

All data collected on our website is processed on the provider's servers. We have concluded a data processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

4) Cookies

To make your visit to our website more attractive and to enable the use of certain functions, we use cookies, which are small text files stored on your device. Some of these cookies are automatically deleted after closing your browser (so-called "session cookies"), while others remain on your device longer and allow us to save your site settings (so-called "persistent cookies"). In the latter case, you can find the storage duration in the cookie settings overview of your web browser.

If personal data is also processed by individual cookies we use, the processing is carried out either in accordance with Art. 6(1) lit. b GDPR for contract performance, in accordance with Art. 6(1) lit. a GDPR in the case of consent given, or in accordance with Art. 6(1) lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit.

You can set your browser to notify you about the setting of cookies and decide individually whether to accept them or to exclude the acceptance of cookies for certain cases or in general.

Please note that if you do not accept cookies, the functionality of our website may be limited.

5) Contacting Us

When contacting us (e.g., via contact form or email), personal data is processed solely for the purpose of processing and responding to your inquiry and only to the extent necessary.

The legal basis for processing these data is our legitimate interest in responding to your inquiry in accordance with Art. 6(1) lit. f GDPR. If your contact is aimed at concluding a contract, then the additional legal basis for processing is Art. 6(1) lit. b GDPR. Your data will be deleted when it can be inferred from the circumstances that the matter in question has been conclusively clarified and provided that there are no statutory retention obligations to the contrary.

6) Data Processing When Opening a Customer Account

According to Art. 6(1) lit. b GDPR, personal data will continue to be collected and processed as necessary when you provide it to us when opening a customer account. The required data for the account opening can be found in the input mask of the corresponding form on our website.

You can delete your customer account at any time by sending a message to the address mentioned above of the controller. After the deletion of your customer account, your data will be deleted unless all contracts concluded via it have been fully processed, there are no statutory retention obligations to the contrary, and we have no legitimate interest in further storage.

7) Use of Customer Data for Direct Advertising

Subscription to our Email Newsletter

If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information required for sending the newsletter is your email address. The provision of further data is voluntary and is used to address you personally. For the newsletter distribution, we use the so-called double opt-in procedure, which ensures that you only receive newsletters if you have expressly confirmed your consent to receive newsletters by clicking on a verification link sent to the provided email address.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6(1) lit. a GDPR. In this context, we store your IP address as registered by the Internet Service Provider (ISP) as well as the date and time of registration to trace any possible misuse of your email address at a later date. The data collected by us when registering for the newsletter will be used strictly for the purpose intended.

You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending a corresponding message to the controller mentioned at the beginning. After unsubscribing, your email address will be immediately deleted from our newsletter distribution list unless you have expressly consented to the further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this statement.

8) Data Processing for Order Handling

8.1 To the extent necessary for the contract processing for delivery and payment purposes, the personal data collected by us will be forwarded in accordance with Art. 6(1) lit. b GDPR to the contracted transport company and the contracted credit institution.

If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we will use the contact data provided by you at the time of the order (name, address, email address) to personally inform you of upcoming updates within the legally stipulated period as part of our statutory information obligations pursuant to Art. 6(1) lit. c GDPR. Your contact details will be used strictly for notifications about updates owed by us and will only be processed to the extent necessary for this information.

For the processing of your order, we also work with the following service provider(s) who support us in whole or in part in executing concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.

8.2 Transfer of Personal Data to Shipping Service Providers

- DPD

We use the following provider as a transport service provider: DPD Deutschland GmbH, Wailandtstraße 1, 63741 Aschaffenburg, Germany

We forward your email address and/or phone number to the provider in accordance with Art. 6(1) lit. a GDPR before the delivery of the goods to coordinate a delivery date or to announce the delivery if you have given your express consent for this in the ordering process. Otherwise, we only forward the name of the recipient and the delivery address to the provider for the purpose of delivery in accordance with Art. 6(1) lit. b GDPR. The data transfer is only carried out to the extent necessary for the delivery of the goods. In this case, it is not possible to coordinate the delivery date with the provider or announce the delivery in advance.

You can revoke your consent at any time with effect for the future, either by notifying the controller mentioned above or the provider.

8.3 Use of Payment Service Providers (Payment Services)

- Amazon Pay

One or more online payment methods from the following provider are available on this website: Amazon Payments Europe s.c.a., 38 avenue J.F. Kennedy, L-1855 Luxembourg

If you select a payment method from the provider where you make an advance payment (such as credit card payment), your payment data (including name, address, bank and card information, currency, and transaction number) provided during the ordering process, as well as information about the content of your order, will be forwarded to the provider in accordance with Art. 6(1) lit. b GDPR. The data transfer is carried out solely for the purpose of processing payments with the provider and only to the extent necessary for this purpose.
- Apple Pay

If you choose the "Apple Pay" payment method from Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, payment processing will be carried out via the "Apple Pay" function of your iOS, watchOS, or macOS-operated device by charging a payment card stored with "Apple Pay." Apple Pay uses security features built into the hardware and software of your device to protect your transactions. To authorize a payment, the entry of a code previously specified by you, as well as verification via the "Face ID" or "Touch ID" function of your device, is required.

For the purpose of payment processing, the information provided by you during the ordering process, along with the information about your order, is transmitted to Apple in encrypted form. Apple then re-encrypts this data with a developer-specific key before the data is transmitted to the payment service provider of the payment card stored with Apple Pay for payment processing. The encryption ensures that only the website from which the purchase was made can access the payment data. After the payment is completed, Apple sends your device account number along with a transaction-specific, dynamic security code to the originating website to confirm the payment success.

If personal data is processed during the described transmissions, the processing is carried out solely for the purpose of payment processing in accordance with Art. 6(1) lit. b GDPR.

Apple stores anonymized transaction data, including the approximate purchase amount, the approximate date and time, as well as an indication of whether the transaction was successfully completed. Anonymization completely excludes any personal reference. Apple uses the anonymized data to improve "Apple Pay" and other Apple products and services.

If you use Apple Pay on the iPhone or Apple Watch to complete a purchase made via Safari on the Mac, the Mac and the authorization device communicate via an encrypted channel on Apple's servers. Apple does not process or store any of this information in a format that could identify you. You can disable the option to use Apple Pay on your Mac in the settings of your iPhone. Go to "Wallet & Apple Pay" and disable "Allow Payments on Mac."

Further privacy information on Apple Pay can be found at the following internet address: https://support.apple.com/en-us/HT203027
- giropay

One or more online payment methods from the following provider are available on this website: paydirekt GmbH, Stephanstr. 14-16, 60313 Frankfurt am Main, Germany

If you select a payment method from the provider where you make an advance payment (such as credit card payment), your payment data (including name, address, bank and card information, currency, and transaction number) provided during the ordering process, as well as information about the content of your order, will be forwarded to the provider in accordance with Art. 6(1) lit. b GDPR. The data transfer is carried out solely for the purpose of processing payments with the provider and only to the extent necessary for this purpose.
- Google Pay

If you choose the "Google Pay" payment method from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), payment processing will be carried out via the "Google Pay" application of your Android 4.4 ("KitKat")-operated and NFC-enabled mobile device by charging a payment card stored with Google Pay or a verified payment system there (e.g., PayPal). For authorizing a payment over 25 EUR via Google Pay, the prior unlocking of your mobile device using the verification measure set up (e.g., face recognition, password, fingerprint, or pattern) is required.

For the purpose of payment processing, the information provided by you during the ordering process, along with the information about your order, is transmitted to Google. Google then transmits your payment information stored in Google Pay in the form of a one-time transaction number to the originating website, with which a completed payment is verified. This transaction number does not contain any information about the actual payment data of your payment methods stored with Google Pay but is created and transmitted as a one-time valid numeric token. In all transactions via Google Pay, Google acts only as an intermediary for processing the payment process. The transaction is exclusively carried out in the relationship between the user and the originating website by charging the payment method stored with Google Pay.

If personal data is processed during the described transmissions, the processing is carried out solely for the purpose of payment processing in accordance with Art. 6(1) lit. b GDPR.

Google reserves the right to collect, store, and evaluate specific process-specific information for each transaction made via Google Pay. This includes the date, time, and amount of the transaction, merchant location and description, a description of the goods or services purchased provided by the merchant, photos attached to the transaction, the seller's and buyer's or sender's and recipient's name and email address, the payment method used, your description of the transaction purpose, and, if applicable, the offer associated with the transaction.

According to Google, this processing is carried out solely in accordance with Art. 6(1) lit. f GDPR based on the legitimate interest in proper accounting, verification of transaction data, and optimization and maintenance of the Google Pay service.

Google also reserves the right to combine the processed transaction data with other information collected and stored by Google through the use of other Google services.

The terms of use of Google Pay can be found here:

https://payments.google.com/payments/apis-secure/u/0/get_legal_document?ldo=0&ldt=googlepaytos&ldl=en
Further privacy information on Google Pay can be found at the following internet address:
https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice&ldl=en
- Klarna

One or more online payment methods from the following provider are available on this website: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden

If you select a payment method from the provider where you make an advance payment (such as credit card payment), your payment data (including name, address, bank and card information, currency, and transaction number) provided during the ordering process, as well as information about the content of your order, will be forwarded to the provider in accordance with Art. 6(1) lit. b GDPR. The data transfer is carried out solely for the purpose of processing payments with the provider and only to the extent necessary for this purpose.

If you select a payment method where the provider makes an advance payment (such as purchase on account or installment purchase or direct debit), you will also be asked during the order process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and, if applicable, data of an alternative payment method).

To protect our legitimate interest in determining the solvency of our customers, this data will be forwarded by us in accordance with Art. 6(1) lit. f GDPR for the purpose of a credit check to the provider. The provider checks based on the personal data provided by you, as well as other data (such as shopping cart, invoice amount, order history, payment experience), whether the payment option selected by you can be granted with respect to payment and/or default risks.

In the course of the application review, in addition to internal criteria, the provider may also include identity and credit information from the following credit agencies in accordance with Art. 6(1) lit. f GDPR:

https://cdn.klarna.com/1.0/shared/content/legal/terms/0/en_us/credit_rating_agencies

The credit report may contain probability values (so-called score values). To the extent that score values are included in the credit report result, they are based on a scientifically recognized mathematical-statistical procedure. In the calculation of the score values, address data, among other things, is included, but not exclusively.

You may object to this processing of your data at any time by sending a message to us or the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.
- Paypal

One or more online payment methods from the following provider are available on this website: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

If you select a payment method from the provider where you make an advance payment, your payment data (including name, address, bank and card information, currency, and transaction number) provided during the ordering process, as well as information about the content of your order, will be forwarded to the provider in accordance with Art. 6(1) lit. b GDPR. The data transfer is carried out solely for the purpose of processing payments with the provider and only to the extent necessary for this purpose.

If you select a payment method where we make an advance payment, you will also be asked during the order process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and, if applicable, data of an alternative payment method).

To protect our legitimate interest in determining your solvency, this data will be forwarded by us in accordance with Art. 6(1) lit. f GDPR for the purpose of a credit check to the provider. The provider checks based on the personal data provided by you, as well as other data (such as shopping cart, invoice amount, order history, payment experience), whether the payment option selected by you can be granted with respect to payment and/or default risks.

The credit report may contain probability values (so-called score values). To the extent that score values are included in the credit report result, they are based on a scientifically recognized mathematical-statistical procedure. In the calculation of the score values, address data, among other things, is included, but not exclusively.

You may object to this processing of your data at any time by sending a message to us or the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.
- Shopify Payments

One or more online payment methods from the following provider are available on this website: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland

If you select a payment method from the provider where you make an advance payment (such as credit card payment), your payment data (including name, address, bank and card information, currency, and transaction number) provided during the ordering process, as well as information about the content of your order, will be forwarded to the provider in accordance with Art. 6(1) lit. b GDPR. The data transfer is carried out solely for the purpose of processing payments with the provider and only to the extent necessary for this purpose.
- SOFORT

One or more online payment methods from the following provider are available on this website: SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany

If you select a payment method from the provider where you make an advance payment (such as credit card payment), your payment data (including name, address, bank and card information, currency, and transaction number) provided during the ordering process, as well as information about the content of your order, will be forwarded to the provider in accordance with Art. 6(1) lit. b GDPR. The data transfer is carried out solely for the purpose of processing payments with the provider and only to the extent necessary for this purpose.
- Stripe

One or more online payment methods from the following provider are available on this website: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland

If you select a payment method from the provider where you make an advance payment (such as credit card payment), your payment data (including name, address, bank and card information, currency, and transaction number) provided during the ordering process, as well as information about the content of your order, will be forwarded to the provider in accordance with Art. 6(1) lit. b GDPR. The data transfer is carried out solely for the purpose of processing payments with the provider and only to the extent necessary for this purpose.

If you select a payment method where the provider makes an advance payment (such as purchase on account or installment purchase or direct debit), you will also be asked during the order process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and, if applicable, data of an alternative payment method).

To protect our legitimate interest in determining the solvency of our customers, this data will be forwarded by us in accordance with Art. 6(1) lit. f GDPR for the purpose of a credit check to the provider. The provider checks based on the personal data provided by you, as well as other data (such as shopping cart, invoice amount, order history, payment experience), whether the payment option selected by you can be granted with respect to payment and/or default risks.

The credit report may contain probability values (so-called score values). To the extent that score values are included in the credit report result, they are based on a scientifically recognized mathematical-statistical procedure. In the calculation of the score values, address data, among other things, is included, but not exclusively.

You may object to this processing of your data at any time by sending a message to us or the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.

9) Web Analytics Services

Google (Universal) Analytics

This website uses Google (Universal) Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables the analysis of your usage of our website.

As a standard, cookies are set by Google (Universal) Analytics when you visit the website, which are stored on your device and collect certain information. This information includes your IP address, which is, however, truncated by Google by the last digits to exclude direct personal identification.

The information is transmitted to Google servers and further processed there. In this process, data may also be transferred to Google LLC, based in the USA.

Google uses the collected information on our behalf to evaluate your use of the website, compile reports on website activities, and provide us with other services related to website and internet usage. The IP address transmitted by your browser as part of Google Analytics and truncated will not be combined with other data from Google. The data collected through the use of Google (Universal) Analytics is stored for a period of two months and then deleted.

All processing described above, in particular, the setting of cookies on your device, will only occur if you have given us your express consent in accordance with Art. 6(1) lit. a GDPR.
Without your consent, Google (Universal) Analytics will not be used during your visit to the website. You can withdraw your consent at any time with future effect. To exercise your right to withdraw consent, please deactivate this service through the "Cookie-Consent-Tool" provided on the website.

We have concluded a data processing agreement with Google, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

Further legal information on Google (Universal) Analytics can be found at https://policies.google.com/privacy?hl=en and at https://policies.google.com/technologies/partner-sites

Demographic Characteristics
Google (Universal) Analytics uses the special feature "demographic characteristics" and can thereby create statistics that provide information about the age, gender, and interests of website visitors. This is done by analyzing advertising and third-party information. This enables the identification of target groups for marketing activities. However, the collected data cannot be associated with a specific person and will be deleted after a storage period of two months.

Google Signals
As an extension of Google (Universal) Analytics, Google Signals can be used on this website to create cross-device reports. If you have activated personalized ads and linked your devices with your Google account, Google can analyze your usage behavior across devices and create database models, including cross-device conversions, subject to your consent to the use of Google Analytics in accordance with Art. 6(1) lit. a GDPR. We do not receive any personal data from Google, only statistics. If you want to stop cross-device analysis, you can deactivate the "Personalized Ads" function in your Google account settings. Follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=en More information on Google Signals can be found at the following link: https://support.google.com/analytics/answer/7532985?hl=en

UserIDs
As an extension of Google (Universal) Analytics, the "UserIDs" feature can be used on this website. If you have consented to the use of Google (Universal) Analytics in accordance with Art. 6(1) lit. a GDPR, have set up an account on this website, and log in on various devices with this account, your activities, including conversions, can be analyzed across devices.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.

10) Rights of the Data Subject

10.1 The applicable data protection law grants you the following data subject rights regarding the processing of your personal data, provided the respective legal requirements are met:

  • Right of access according to Art. 15 GDPR;
  • Right to rectification according to Art. 16 GDPR;
  • Right to erasure according to Art. 17 GDPR;
  • Right to restriction of processing according to Art. 18 GDPR;
  • Right to notification according to Art. 19 GDPR;
  • Right to data portability according to Art. 20 GDPR;
  • Right to withdraw consent granted according to Art. 7(3) GDPR;
  • Right to lodge a complaint according to Art. 77 GDPR.

10.2 RIGHT TO OBJECT

IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR OVERRIDING LEGITIMATE INTEREST IN THE CONTEXT OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, WITH FUTURE EFFECT.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS, AND FREEDOMS, OR IF THE PROCESSING SERVES THE ASSERTION, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.

IF WE PROCESS YOUR PERSONAL DATA FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH ADVERTISING PURPOSES AT ANY TIME. YOU CAN EXERCISE YOUR RIGHT TO OBJECT AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA FOR DIRECT MARKETING PURPOSES.

11) Duration of Storage of Personal Data

The duration of storage of personal data is determined based on the respective legal basis, the purpose of processing, and, if applicable, additionally based on the respective statutory retention period (e.g., commercial and tax retention periods).

When processing personal data based on express consent in accordance with Art. 6(1) lit. a GDPR, the data concerned will be stored until you revoke your consent.

If there are statutory retention periods for data processed within the scope of legal or similar obligations based on Art. 6(1) lit. b GDPR, this data will be routinely deleted after the expiration of the retention periods, provided that it is no longer required for the fulfillment of the contract or initiation of the contract and/or there is no legitimate interest on our part in further storage.

When processing personal data based on Art. 6(1) lit. f GDPR, this data will be stored until you exercise your right to object according to Art. 21(1) GDPR unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the assertion, exercise, or defense of legal claims.

When processing personal data for direct marketing purposes based on Art. 6(1) lit. f GDPR, this data will be stored until you exercise your right to object according to Art. 21(2) GDPR.

Unless otherwise stated in the other information contained in this declaration regarding specific processing situations, stored personal data will otherwise be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.