§ 1 Information on the Collection of Personal Data
(2) The controller pursuant to Article 4 (7) of the EU General Data Protection Regulation (GDPR) is:
You can reach our data protection officer at the following address:
Data Protection Officer: Henning Maiwald
80 Pine Street, Floor 24
New York, NY 10005
(3) When you contact us by e-mail or via a contact form, the data you provide (e.g. your e-mail address, your name and your telephone number) will be stored by us to answer your questions. We delete the data arising in this context after the storage is no longer necessary or limit the processing if there are legal storage obligations. For optimal processing of your inquiries, we use the ticket system of Zendesk Inc. Further information on this company can be found under §12.
(4) When using the review function, acc. GDPR Art. 6 para. 1 lit. f), IP addresses are stored for 30 days to protect against misuse. The name is given voluntarily, so any pseudonym can also be used. After checking the review for correctness, your evaluation will be published on the product page of the reviewed product. After publication, your review can be viewed by all visitors on the corresponding product page. If desired, your review can be deleted. To do this, send an e-mail to email@example.com.
(5) If we use contracted service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail below about the respective processes. We also specify the defined criteria for the storage period.
§ 2 Your Rights
(1) You have the following rights vis-à-vis us with regard to your personal data:
- Right to information;
- Right to rectification and erasure;
- Right to restriction of processing;
- Right to object to processing;
- Right to data portability.
(2) You also have the right to complain to a data protection supervisory authority about the processing of your personal data by us. The competent supervisory authority for PROFISHOP is:
The State Commissioner for Data Protection and Freedom of Information:
Frau Dr. Imke Sommer
Tel.: +49 421 3612010
Fax: +49 421 49618495
§ 3 Collection of Personal Data when Visiting our Website
(1) When using the website for information purposes only, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure stability and security (legal basis is Art. 6 Para. 1 Sent. 1 f) GDPR):
- IP address;
- Date and time of the request
- Time zone difference to Greenwich Mean Time (GMT);
- Content of the request (specific page);
- Access status/HTTP status code;
- Amount of data transferred;
- Website from which the request comes;
- Operating system and its interface;
- Language and version of the browser software.
(2) In addition to the aforementioned data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive and assigned to the browser you are using and through which certain information flows to the site that sets the cookie (in this case by us). Cookies cannot run programs or transmit viruses to your computer. They serve to make the Internet offer more user-friendly and effective overall.
a) This website uses the following types of cookies, the scope and functionality of which are explained below:
- Transient cookies (hereinafter referred to in lit. b);
- Persistent cookies (hereinafter referred to in lit. c.).
b) Transient cookies are automatically deleted when you close the browser. These include, in particular, session cookies. These store a so-called “Session ID” with which various requests from your browser can be assigned to the common session. This allows your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close the browser.
c) Persistent cookies are automatically deleted after a specified period, which may differ depending on the cookie. You can delete the cookies by way of the security settings of your browser at any time.
d) You can configure your browser settings according to your wishes and, for example, refuse the acceptance of third-party cookies or all cookies. We would like to point out that you may not be able to use all functions of this website.
f) The Flash cookies used are not recorded by your browser, but by your Flash plug-in. We also use HTML5 storage objects that are stored on your device. These objects store the required data regardless of your browser used and do not have an automatic expiration date. If you do not want Flash cookies to be processed, you must install an appropriate add-on, e.g. “Better Privacy” for Mozilla Firefox (https://addons.mozilla.org/de/firefox/addon/betterprivacy/) or the Adobe Flash Killer Cookie for Google Chrome. You can prevent the use of HTML5 storage objects by using private mode in your browser. We also recommend that you regularly delete your cookies and browser history manually.
§ 4 Collection of Personal Data for Order Processing
In order to fulfil the contract (an order with PROFISHOP), further personal data is required to ensure the delivery of the goods (e.g. name, address and contact details). The data is therefore processed within the meaning of Art. 6 Para. 1 lit. b) GDPR. In order to fulfil the contract, the aforementioned personal data will be passed on to the manufacturers involved in the order and their freight forwarders (for more detailed information see §5 Disclosure of Personal Data).
§ 4 a Use of the e-mail address for the purpose of e-mail advertising
We will use your e-mail address for advertising purposes and send you offers for similar goods or services (in the sale of the purchased goods and services) if you have not objected to such use upon the collection of data or subsequently objected with effect for the future. The data is then used on the basis of the Art. 6 Para. 1 lit f) GDPR. It is used to draw your attention to interesting offers. You can object to the use of the e-mail address for advertising purposes at any time with effect for the future, for example, by sending an e-mail to firstname.lastname@example.org without incurring any costs other than the transmission costs according to the base rates.
If you separately consent to receiving our newsletter, we will send you the newsletter until the consent has been revoked. The data is then used on the basis of the Art. 6 Para. 1 lit. a) GDPR.
§ 5 Disclosure of Personal Data
The personal data you send to us will only be disclosed for the fulfillment of the order in accordance with Art. 6 Para. 1 lit. b) GDPR. The data will only be passed on to the order-related manufacturers and forwarders. Without the disclosure of this data, the order cannot be fulfilled. The personal data transmitted includes name, address and contact details.
§ 6 Objection to the Processing of your Data or Revocation of Consent to the Processing of your Data
(1) If you have given your consent to the processing of your data, you can revoke it at any time. Such a revocation affects the admissibility of the processing of your personal data after you have issued it to us.
(2) Insofar as we base the processing of your personal data on the balance of interests, you can object to the processing. This is the case if the processing is in particular not necessary for the performance of a contract with you, which is described by us in the following description of functions. When exercising such an objection, we ask you to explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will examine the situation and either discontinue or adapt the data processing, or we will point out to you our compelling reasons worthy of protection, on the basis of which we will continue to process the data.
(3) Of course, you can object to the processing of your personal data for the purposes of advertising and data analysis at any time. You can inform us about your objection to your personal data being used for advertising purposes under the following contact details: PROFISHOP Inc., 80 Pine Street, Floor 24, New York, NY 10005, United States; by e-mail: email@example.com.
§ 7 Payment Methods at PROFISHOP
For the provision of the payment methods at PROFISHOP, the personal data required will be forwarded to one of the following partners, depending on the selected payment method:
(1) Credit check by CRIF Bürgel
We carry out a credit check before concluding the purchase agreement. This is done to check whether we can offer you the payment method Purchase on account (according to Art. 6 Para. 1 lit. b) GDPR) and to protect us in the event of a possible payment default. In addition, the credit check serves your and our security, as this prevents fraud and other crimes (according to Art. 6 Para. 1 lit. f) GDPR). For credit checks, we transmit the personal data required for a credit check (first and last name, your address and, if applicable, your date of birth) to the following credit service providers: CRIF Bürgel GmbH, Radlkoferstraße 2, 81373 Munich, Germany.
This service provider uses the aforementioned data transmitted by us to carry out a corresponding assessment of your creditworthiness with regard to the respective order on the basis of mathematical-statistical procedures (scoring). Furthermore, this service provider uses the aforementioned data for other companies (e.g. other online retailers) for the purpose of address verification or identity checks as well as for scoring applications based on this. Your address data is also taken into account during the calculation of the probability value. Under certain circumstances, a conclusion could be drawn based on negative characteristics. If you do not agree with the payment methods offered to you, you can inform us thereof in writing by letter or by email to firstname.lastname@example.org. We will then review the decision again, taking into account your point of view. You can revoke your consent at any time with effect for the future in writing or in text form, that is by sending an e-mail to email@example.com, as well as receive information from us about the stored data and the service provider we use to assess creditworthiness (at the above addresses). Information on the activities of CRIF Bürgel GmbH can be found online at www.crifbuergel.de/de/datenschutz.
(2) Full Payment Service Provider Stripe Ltd.
PROFISHOP uses the service provider Stripe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, for the processing of payments by credit card, to whom we pass on the following information about your order (name, address, account number, bank code, credit card number, if applicable, invoice amount, currency and transaction number) in accordance with Art. 6 Para. 1 lit. b DSGVO. The transfer of your data is solely for the purpose of payment processing with Stripe and only insofar as it is necessary for this purpose.
You can find data protection information on Stripe here: https://stripe.com/privacy
(3) SOFORT (Klarna)
You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.
§ 8 Liability for Content and Liability for Links
(1) The contents of our pages were created with great care. However, we cannot assume any liability for the correctness, completeness and topicality of the contents. As a service provider, we are responsible for our own content on these pages according to the general laws responsible and in accordance with § 7 Para. 1 Telemedia Act (TMG). According to §§ 8 to 10 of the Telemedia Act, however, we as a service provider are not obliged to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity. Obligations to remove or block the use of information under general law remain unaffected. However, liability in this regard is only possible from the time of knowledge of a specific infringement. If we become aware of such violations, we will remove that content immediately.
(2) Our offer contains links to external websites of third parties, over the contents of which we have no influence. Therefore, we cannot assume any liability for such third-party content. The respective provider or operator of the pages is always responsible for the content of the linked pages. The linked pages were checked for possible legal violations at the time of linking. Illegal contents were not recognizable at the time of linking. However, a permanent control of the content of the linked pages is not reasonable without concrete evidence of an infringement. Upon notification of violations, we will remove such links immediately.
§ 9 Copyright
The content and works on these pages created by the site operators are subject to German copyright law. The duplication, processing, editing, distribution and any kind of exploitation outside the limits of copyright law require the written consent of the respective author or creator. Downloads and copies of this site are only permitted for private, non-commercial use. Insofar as the content on this site was not created by the operator, the copyrights of third parties are respected. In particular, contents of third parties are marked as such. Should you nevertheless become aware of a copyright infringement, please inform us accordingly. Upon notification of violations, we will remove such content immediately.
§ 10 Newsletter
(1) Registration for the newsletter is voluntary and can be revoked at any time. In order to send the free newsletter, we need your e-mail address if you have agreed to receive the newsletter. After submitting the registration form, you will receive a confirmation e-mail from us. The order will only take effect once you have clicked on the link in the confirmation e-mail (double opt-in procedure). You can unsubscribe from the newsletter at any time. Your e-mail address will then be immediately deleted from the distribution system.
This website uses GetResponse to send newsletters. The provider is GetResponse S.A.. z o.o., with registered office in Gdansk, Poland, ul. Grunwaldzka 413 (NEON), 80-309 Gdansk, website: https://www.getresponse.com. GetResponse is a service that can be used to organize and analyze the sending of newsletters. The data you enter for the purpose of receiving the newsletter (e.g. e-mail address) will be stored on the servers of GetResponse in Europe.
Our newsletters sent with GetResponse enable us to analyse the behaviour of newsletter recipients. Among other things, it can be analyzed how many recipients have opened the newsletter message and how often which link was clicked in the newsletter. With the help of so-called conversion tracking, it can also be analyzed whether a predefined action (e.g. purchase of a product on our website) has taken place after clicking on the link in the newsletter. Further information on data analysis by GetResponse newsletter can be found at: https://www.getresponse.com/features/email-marketing/email-analytics.
The data processing takes place on the basis of your consent (Art. 6 Para. 1 lit. a GDPR). You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation. If you do not want an analysis by GetResponse, you must unsubscribe from the newsletter. For this purpose, we provide a corresponding link in every newsletter message. You can also unsubscribe from the newsletter directly on the website.
The data you have stored with us for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted from our servers as well as from the servers of GetResponse after unsubscribing from the newsletter. Data that has been stored with us for other purposes (e.g. e-mail addresses for the member area) will remain unaffected.
§ 11 Use of Zendesk for Customer Support
To process customer inquiries, PROFISHOP uses the ticket system Zendesk, a customer service platform of Zendesk Inc., 989 Market Street #300, San Francisco, CA 94102, USA. For this purpose, necessary data such as first name, last name, postal address, telephone number, e-mail address are collected via our website in order to be able to answer your request. Zendesk is a certified participant in the so-called “Privacy Shield Framework” and thus meets the minimum requirements for legally compliant order data processing.
§ 12 Applicant Management
(1) Data recipients
Within our company, we only pass on your personal data to the areas and persons who need this data to fulfil contractual and legal obligations or to implement our legitimate interest. Otherwise, data will only be passed on to recipients outside the company to the extent permitted or required by law, if the disclosure is necessary to fulfil legal obligations or if we have your consent. Applications are processed with the help of the personnel management system of Personio GmbH. This complies with all requirements of the EU General Data Protection Regulation. Further information can be found at: https://www.personio.de/datenschutz/
(2) Further processing of data
If there is an employment relationship between you and us, we may process the personal data already received from you for the purposes of the employment relationship in accordance with Art. 88 GDPR in conjunction with § 26 Federal Data Protection Act (BDSG-neu), insofar as this is necessary for the implementation or termination of the employment relationship or for the exercise or fulfillment of the rights and obligations of the representation of the interests of employees resulting from a law or a collective agreement, a company or service agreement (collective agreement).
(3) Categories of data
We only process data related to your application. This may include general data about your person (name, address, contact details, etc.), information about your professional qualifications and school education, information about professional training and, if applicable, other data that you send us in connection with your application.
(4) Sources of data
We process personal data that we have received in the course of contacting you via the application form or your application sent to us by mail or e-mail to firstname.lastname@example.org.
(5) Duration of data retention
We store your personal data only for as long as is necessary to decide on your application. Your personal data or application documents will be deleted a maximum of six months after the end of the application process (e.g. the announcement of the rejection decision), unless a longer storage period is legally required or permitted. Furthermore, we store your personal data only insofar as this is required by law or in a specific case for the assertion, exercise or defence of legal claims for the duration of a legal dispute. In the event that you have consented to a longer storage of your personal data, we will store it in accordance with your declaration of consent. If there is an employment relationship, training relationship or internship relationship following the application process, your data will, as far as necessary and permissible, initially continue to be stored and then transferred to the personnel file.
§ 13 Use of Web Analysis Tools
The following web analysis tools (web analysis “cookies”) are set on our website. The legal basis for the use of these “cookies” is your consent (Art. 6 Para.1 a GDPR). When you visit our site for the first time, you can use the automatically displayed “cookie” banner to individually grant or withdraw consent for each of the cookies listed below. If you visit our website again, you can click on the “cookie settings” button under “Legal” and check or change your individual cookie settings there. If you have not expressly agreed to the use of this cookie under “adjust cookie settings” on our website, it will not be set on our website.
(1) Facebook retargeting
(2) Facebook tracking pixels
On this website we use the “tracking pixel” from Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”). This pixel can be used to track the behavior of users after they have been redirected to our website by clicking on a Facebook ad. This allows us to track the effectiveness of Facebook ads for statistical and market research purposes. The data collected in this way is anonymous to us, i.e. we do not see the personal data of individual users. However, this data is stored and processed by Facebook, about which we inform you according to our level of knowledge. Facebook can connect this data with your Facebook account and also use it for its own advertising purposes, in accordance with Facebook's data usage policy https://www.facebook.com/about/privacy/. You have the option to prohibit Facebook and its partners from placing advertisements. You can edit the settings for Facebook's ads at the following link: https://www.facebook.com/ads/website_custom_audiences/.
(3) Google AdWords
PROFISHOP Inc. uses the online advertising program “Google AdWords” and the function “Conversion Tracking” as part of the Google AdWords program. The provider is Google Ireland Limited, in Gordon House, Barrow Street, Dublin 4, Ireland. For conversion tracking via Google AdWords, a cookie is placed by the company Google Inc. on your computer if you have reached our website via an ad placed by Google. These cookies lose their validity after 30 days and are not used to personally identify users and visitors to the online shop. If the user visits certain pages of the online shop of PROFISHOP Inc. and the cookie set by Google has not yet expired, Google and PROFISHOP Inc. can recognize that the user has clicked on the ad and was redirected to the page prepared in advance. Each customer receives a different cookie, i.e. cookies cannot be tracked via the website of PROFISHOP Inc..
The information collected with the help of the conversion cookie is used to compile statistics on certain aspects of user behavior (e.g. conclusion of a purchase contract). The data collected by conversion tracking includes the total number of users who clicked on an ad placed as part of the Google Adwords program and were redirected to a page with a conversion tracking tag. Neither PROFISHOP Inc. nor Google Ireland Limited receive information with which a personal identification of the visitor or customer is possible. A connection between your personal data and your usage data is not possible. If you want to disable cookies for conversion tracking, you can set your browser to block cookies from the following domain: “googleadservices.com”. Further information on the subject of “data protection” in the context of Google AdWords can be found at the following link: http://www.google.de/privacy_ads.html
(4) Google Analytics
The Terms and Conditions of Use and further information on data protection can be found at http://www.google.com/analytics/terms/de.html or at
(5) Google DoubleClick
(6) Google reCAPTCHA
(7) Microsoft Bing Ads Conversion Tracking
Our online offers use conversion tracking from Microsoft (Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA). Microsoft Bing Ads sets a cookie on your computer if you have reached our website via a Microsoft Bing ad. Microsoft Bing and we can recognize in this way that someone clicked on an ad, was redirected to our website and reached a previously determined landing page (conversion page). We only know the total number of users who clicked on a Bing ad and were then redirected to the conversion page. No personal information about the identity of the user is provided. If you do not want to participate in the tracking process, you can also refuse the setting of a cookie required for this – for example via a browser setting that generally deactivates the automatic setting of cookies. Further information on data protection and the cookies used at Microsoft Bing can be found on the Microsoft website: https://privacy.microsoft.com/de-de/privacystatement
(8) billiger.de Tracking
The products of PROFISHOP are displayed on the website billiger.de, a service offered by solute gmbh (Zeppelinstraße 15, 76185 Karlsruhe, Germany). Billiger.de uses, among other things, cookies that are stored on your computer and that allow an analysis of the use of the website. Within the scope of use, data, such as and in particular the IP address and surfing activities of the users, can be transmitted to a server of solute gmbh and stored there. Solute gmbh may transfer this information to third parties if this is required by law, if your consent is given, or if this data is processed by third parties. You can prevent the collection and forwarding of personal data (especially your IP address) and the processing of this data by deactivating the execution of Java Script in your browser or installing a tool such as 'NoScript'. Further information on data protection when using billiger.de can be accessed under the following link: http://www.billiger.de/service/datenschutz.html
(9) guenstiger.de Tracking
The products of PROFISHOP are displayed on the website guenstiger.de (guenstiger.de GmbH, Deichstraße 34, 20459 Hamburg, Germany). Guenstiger.de uses, among other things, cookies that are stored on your computer and that allow an analysis of the use of the website. As part of the use of our website, personal data may be transmitted to a server of guenstiger.de and stored there. guenstiger.de will not share this information with third parties. For more information about the stored data, please visit: http://www.guenstiger.de/Text/Datenschutz.html
(10) Embedding function from YouTube
The website of PROFISHOP uses the YouTube embedding function for the display and playback of videos from YouTube. We use the extended data protection mode, which, according to the provider, does not initiate storage of user information until the video is played. The moment the playback of the embedded video is started, the provider, YouTube, activates a cookie to collect information about user behavior.
According to YouTube, the cookie is used, among other things, to collect video statistics, to improve user-friendliness and to prevent abusive practices.
(11) Criteo Tracking
The website of PROFISHOP websites are combined using technology from Criteo GmbH, Gewürzmühlstraße 11, 80538 Munich, Germany. Pseudonymized information about the surfing behavior of website visitors is stored for marketing purposes. This data is stored in cookies on the visitor's computer. The cookies use algorithms to analyse the pseudonymised surfing behaviour of the visitor in order to subsequently be able to display targeted product recommendations as personalised advertising banners on other websites (so-called publishers). Criteo does not collect data with direct personal reference, such as your name, IP address or other data that clearly refers to you. The set cookie is given an arbitrary identifier. If the cookie is deleted, it is lost.
(12) LinkedIn Insight
The website of PROFISHOP uses LinkedIn Insight. The LinkedIn Insight tag allows you to collect information about visits to your website, including URL, referrer URL, IP address, device and browser properties (user agent), and time stamps. The IP addresses are truncated or hashed (if they are used to reach members across devices). Members' direct identifiers are removed within seven days to pseudonymize the data. This remaining pseudonymized data will then be deleted within 180 days.
(13) Google Places API (Address completion)
The PROFISHOP website uses the Google Places API Web Service for Google's automatic address completion. Provider of the service is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
In order to receive this information from Google, your IP address and your entered content will be transmitted to Google in the address field.
For data production, the browser you use must connect to Google's servers. As a result, Google becomes aware that our website has been accessed via your IP address. Such use by Google takes place within the meaning of Art. 6 Para. 1 lit. f GDPR. A legitimate interest is the simplification of the address information on our website.
Current as of: Nov. 10, 2020