Table of Contents
As of February 2026
- Name and address of the controller
- Contact details of the data protection officer
- General information on data processing
- Rights of the data subject
- Provision of the website and creation of log files
- Use of cookies
- Online shop
- Ordering in the online shop
- Payment methods
- Shipping service providers
- Email contact
- Contact form
- Affiliate programmes
- Review portal
- Email delivery
- Content Delivery Networks
- Use of Matomo analytics software
- Use of Google Analytics
- Use of LiveChat
- Use of Meta Tracking Pixel
- Plugins used
1. Name and address of the controller
The controller within the meaning of the General Data Protection Regulation and other national data protection laws of the Member States as well as other data protection provisions is:
myfolie GmbH
Von-Stauffenberg-Str, 27
82008 Unterhaching
Germany
2. Contact details of the data protection officer
The data protection officer of the controller is
DataCo GmbH
Dachauer Straße 65
80335 Munich
Germany
+49 89 / 7400 45840
www.dataguard.de
3. General information on data processing
I.) Scope of the processing of personal data
As a matter of principle, we process the personal data of our users only insofar as this is necessary to provide a functioning online shop as well as our content and services. The processing of our users’ personal data is generally carried out only with the user’s consent. An exception applies in cases where it is not possible to obtain consent in advance for factual reasons and the processing of the data is required by law.
II.) Legal basis for the processing of personal data
Where we obtain the consent of the data subject for processing operations involving personal data, Art. 6 para. 1 sentence 1 lit. a GDPR serves as the legal basis.
When processing personal data that is necessary for the performance of a contract to which the data subject is a party, Art. 6 para. 1 sentence 1 lit. b GDPR serves as the legal basis. This also applies to processing operations that are necessary to carry out pre-contractual measures.
Where the processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Art. 6 para. 1 sentence 1 lit. c GDPR serves as the legal basis.
In the event that vital interests of the data subject or another natural person make the processing of personal data necessary, Art. 6 para. 1 sentence 1 lit. d GDPR serves as the legal basis.
If processing is necessary to safeguard a legitimate interest of our company or a third party and the interests, fundamental rights and freedoms of the data subject do not override this interest, Art. 6 para. 1 sentence 1 lit. f GDPR serves as the legal basis for processing.
III.) Data erasure and storage period
The personal data of the data subject will be erased or blocked as soon as the purpose of storage no longer applies. Data may also be stored if this has been provided for by the European or national legislator in Union regulations, laws or other provisions to which the controller is subject. The data will also be blocked or erased if a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of the data for the conclusion or performance of a contract.
4. Rights of the data subject
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights against the controller:
I.) Right of access (Art. 15 GDPR)
You have the right to request confirmation from us as to whether personal data concerning you is being processed.
- If this is the case, you have the right to access this data and to the following information:
- Purposes of processing
- Categories of personal data
- Recipients or categories of recipients
- Planned storage period or the criteria for determining this period
- Existence of the rights to rectification, erasure or restriction or to object
- Right to lodge a complaint with the competent supervisory authority
- Where applicable, the origin of the data (if collected from a third party)
- Where applicable, the existence of automated decision-making, including profiling, with meaningful information about the logic involved, the scope and the expected effects
- Where applicable, transfer of personal data to a third country or international organisation
II.) Right to rectification (Art. 16 GDPR)
If your personal data is incorrect or incomplete, you have the right to request the immediate correction or completion of the personal data.
III.) Right to restriction of processing (Art. 18 GDPR)
If one of the following requirements is met, you have the right to request restriction of the processing of your personal data:
- You dispute the accuracy of your personal data, for a period enabling us to verify the accuracy of the personal data.
- In the event of unlawful processing, you refuse the erasure of the personal data and request instead the restriction of the use of the personal data.
- We no longer need your personal data for the purposes of processing, but you require your personal data for the establishment, exercise or defence of legal claims, or
- after you have objected to processing, for the duration of the verification of whether our legitimate grounds override your grounds.
IV.) Right to erasure ("right to be forgotten") (Art. 17 GDPR)
If one of the following grounds applies, you have the right to request the immediate erasure of your personal data:
- Your data is no longer necessary for the processing purposes for which it was originally collected.
- You withdraw your consent and there is no other legal basis for processing.
- You object to processing and there are no overriding legitimate grounds for processing, or you object pursuant to Art. 21 para. 2 GDPR.
- Your personal data has been processed unlawfully.
- Erasure is necessary for compliance with a legal obligation under Union law or the law of the Member State to which we are subject.
- The personal data was collected in relation to information society services offered pursuant to Art. 8 para. 1 GDPR.
Please note that the above-mentioned grounds do not apply insofar as processing is necessary:
- For exercising the right of freedom of expression and information;
- For compliance with a legal obligation or for the performance of a task carried out in the public interest and to which we are subject.
- For reasons of public interest in the area of public health.
- For archiving purposes in the public interest, scientific or historical research purposes or statistical purposes.
- For the establishment, exercise or defence of legal claims.
V.) Right to information
If you have exercised your right to rectification, erasure or restriction of processing against the controller, the controller is obliged to inform all recipients to whom the personal data concerning you has been disclosed of this rectification or erasure of the data or restriction of processing, unless this proves impossible or involves disproportionate effort. You have the right to be informed by the controller about these recipients.
VI.) Right to data portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used and machine-readable format or to request that it be transmitted to another controller.
VII.) Right to object to specific data processing (Art. 21 GDPR)
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6 para. 1 sentence 1 lit. e or f GDPR. This also applies to profiling based on these provisions. If personal data concerning you is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
VIII.) Right to withdraw consent under data protection law
You have the right to withdraw your consent under data protection law at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent up to the time of withdrawal.
IX.) Automated decision-making in individual cases, including profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. This does not apply if the decision is necessary for entering into or performing a contract between you and the controller, is authorised by Union or Member State law to which the controller is subject and that law contains suitable measures to safeguard your rights and freedoms and your legitimate interests, or is based on your explicit consent.
However, these decisions must not be based on special categories of personal data pursuant to Art. 9 para. 1 GDPR, unless Art. 9 para. 2 lit. a or b GDPR applies and suitable measures have been taken to protect your rights and freedoms and your legitimate interests. In the cases referred to in a. and c., the controller shall take suitable measures to safeguard your rights and freedoms and your legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express your own point of view and to contest the decision.
X.) Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of personal data concerning you infringes the GDPR. The supervisory authority with which the complaint has been lodged shall inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy under Art. 78 GDPR. A list of the supervisory authorities with local jurisdiction in Germany can be found on the website of the Federal Commissioner for Data Protection at the following link:
https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html
5. Provision of the website and creation of log files
I.) Description and scope of data processing
Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing computer.
The following data is collected:
- Information about the browser type and version used
- The user’s operating system
- The user’s internet service provider
- The user’s IP address
- Date and time of access
- Websites from which the user’s system reaches our website
- Websites accessed by the user’s system via our website
This data is stored in the log files of our system. This data is not stored together with other personal data of the user.
II.) Purpose of data processing
The temporary storage of the IP address by the system is necessary to enable delivery of the website to the user’s computer. For this purpose, the user’s IP address must remain stored for the duration of the session.
Storage in log files takes place to ensure the functionality of the website. The data also serves to optimise the website and ensure the security of our information technology systems. The data is not evaluated for marketing purposes in this context.
These purposes also constitute our legitimate interest in data processing pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR.
III.) Legal basis for data processing
The legal basis for the temporary storage of the data and the log files is Art. 6 para. 1 sentence 1 lit. f GDPR.
IV.) Storage period
The data is erased as soon as it is no longer required to achieve the purpose for which it was collected. In the case of data being collected for the provision of the website, this is the case when the respective session has ended.
In the case of data being stored in log files, this is the case after seven days at the latest. Further storage is possible. In this case, the users’ IP addresses are erased or altered so that the accessing client can no longer be identified.
V.) Possibility of objection
The collection of data for the provision of the website and the storage of data in log files is strictly necessary for the operation of the website. The user may object to this. Whether the objection is successful must be determined as part of a balancing of interests.
6. Use of cookies
I.) Description and scope of data processing
When you visit our website, we use technical tools for various functions, in particular cookies, which may be stored on your device. When accessing our website and at any later time, you can choose whether to generally allow cookies to be set or which individual additional functions you wish to select. You can make changes in your browser settings or via our consent manager. Cookies are text files or information in a database that are stored on your hard drive and assigned to the browser you use, so that certain information can flow to the party that sets the cookie. Below we describe the type of cookies we use: We use technically necessary cookies that are required for the technical structure of the website. Without these cookies, our website may not be displayed (fully correctly) or the support functions may not be available.
The following data is stored and transmitted by the technically necessary cookies:
- Session ID
- Cookie settings
We also use cookies on our website that enable an analysis of users’ browsing behaviour.
This may transmit the following data:
The user data collected in this way is pseudonymised by technical measures. It is therefore no longer possible to assign the data to the accessing user without obtaining additional information. The data is not stored together with other personal data of the users.
II.) Purpose of data processing
The purpose of using technically necessary cookies is to ensure the functionality of our website. Some functions of our website cannot be offered without the use of cookies. For these functions, it is necessary for the browser to be recognised again after a page change.
We require technically necessary cookies for the following applications:
- Shopping cart
- Functionality of the website
- Cookie settings
III.) Legal basis for data processing
The provisions of the Telecommunications and Telemedia Data Protection Act (TTDSG) apply to the storage of information in the end user’s terminal equipment and/or access to information already stored in the end user’s terminal equipment. If the setting and reading of cookies is technically necessary, this is done to ensure the functionality of our website. In this case, the storage of and access to cookies on your terminal equipment is based on § 25 para. 2 no. 2 TTDSG. This storage and access to the information in your terminal equipment serves to make it easier for you to use our website and to offer you our services as requested. Some functions of our website also do not work without the use of these cookies and therefore could not be offered. The cookies are generally erased after the end of the session (e.g. logging out or closing the browser) or after a specified period has elapsed. Information about different storage periods for cookies can be found in the following sections of this privacy policy.
IV.) Storage period, objection and removal options
The user has the option to withdraw consent to the processing of personal data at any time. Cookies are stored on the user’s computer and transmitted by it to our website. As a user, you therefore have full control over the use of cookies. By changing the settings in your internet browser, you can deactivate or restrict the transmission of cookies. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies are disabled for our website, it may no longer be possible to use all website functions to their full extent.
The transmission of Flash cookies cannot be prevented via the browser settings, but can be prevented by changing the Flash Player settings.
If you use a Safari browser version 12.1 or later, cookies are automatically deleted after seven days. This also applies to opt-out cookies set to prevent tracking measures.
7. Online shop
We offer an online shop on our website. For this purpose, we use specially developed online shop software.
The website and online shop are hosted on our own servers. Third parties have no access to server log files.
The servers automatically collect and store information in so-called server log files, which your browser automatically transmits when you visit the website. The stored information is:
- Browser type and browser version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Date and time of the server request
- IP address
No merging of this data with other data sources takes place. This data is collected on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website; server log files must be collected for this purpose. The website server is geographically located in Germany.
7.1. Customer account and storage of designs
I.) Description and scope of data processing
You have the option of creating a customer account on our website.
As part of the registration and use of the customer account, the following personal data is processed in particular:
- First and last name
- Email address
- Password (stored in encrypted form)
- Billing and delivery address
- Telephone number (optional)
- Order history
- Payment status
- Uploaded designs, graphics and print data
- Saved drafts and configurations
For business customers (B2B), the following may also be processed:
- Company name
- Contact person
- VAT identification number
- Where applicable, internal reference numbers
Uploaded designs are stored as part of contract performance and for reuse by the customer.
II.) Purpose of data processing
Processing takes place for the purpose of:
Setting up and managing the customer account
Processing and handling orders
Storing designs for reuse
Processing complaints
Compliance with statutory retention obligations
III.) Legal basis
Processing is based on:
- Art. 6 para. 1 sentence 1 lit. b GDPR (performance of a contract)
- Art. 6 para. 1 sentence 1 lit. c GDPR (legal obligations)
- Art. 6 para. 1 sentence 1 lit. f GDPR (legitimate interest in providing a user-friendly customer account)
Insofar as designs are stored beyond the mere processing of the contract, processing may also be based on consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR.
IV.) Storage of designs and uploaded content
Designs, graphics and print data uploaded by customers are stored:
- For producing the ordered products
- To enable repeat orders
- For processing warranty and complaint cases
If a customer account exists, saved designs remain stored until the customer account is deleted, unless statutory retention obligations or technical requirements prevent this.
After deletion of the customer account, personal data and saved designs are deleted unless statutory retention obligations apply.
Deletion from backup copies takes place as part of the usual technical deletion cycles.
V.) Responsibility for uploaded content
The user is responsible for ensuring that the uploaded content:
- Does not infringe the rights of third parties (e.g. copyrights, trademark rights, personal rights)
- Does not contain special categories of personal data pursuant to Art. 9 GDPR unless a separate legal basis exists for this
- We only check the content of uploaded designs randomly or for production-related reasons.
8. Ordering in the online shop
I.) Description and scope of data processing
We offer our customers the opportunity to design their own motifs and texts online and order them as adhesive film. After completion of the ordering process, we receive personal data that we require to process the order. Mandatory information required for processing the contracts is marked separately; further information provided to us by uploading photos or contact details to be printed on the ordered adhesive film is voluntary. The personal data printed on the adhesive film may be forwarded to external service providers such as graphic designers. All other personal data is not transmitted to service providers outside the company.
II.) Purpose of data processing
The transmission of the personal data voluntarily provided by you serves to process the contract and create the product when you purchase adhesive film.
III.) Legal basis for data processing
The legal basis for data processing is Art. 6 para. 1 sentence 1 lit. b GDPR, as processing the data is necessary to process the concluded purchase contract.
IV.) Storage period
We delete graphics/photos that you upload so that they can be printed on the adhesive film after expiry of the statutory retention obligations (for refund/warranty reasons).
All payment data and data relating to any chargebacks are stored only for as long as they are required for payment processing, the possible processing of returned direct debits and debt collection, and the prevention of misuse.
Payment data may also be stored beyond this period if and for as long as this is necessary to comply with statutory retention periods or to investigate a specific case of misuse.
Your personal data will be deleted upon expiry of the statutory retention obligations, i.e. after 10 years at the latest.
9. Payment methods
I.) Description and scope of data processing
We offer our customers various payment methods for processing their orders. Depending on the payment method, we redirect customers to the platform of the relevant payment service provider. After completion of the payment process, we receive the customers’ payment data from the payment service providers or our bank and process it in our systems for invoicing and accounting purposes.
Payment via Amazon Pay
You have the option of processing the payment via the payment service provider AmazonPay. AmazonPay enables online payments to third parties using the payment and shipping information stored in your Amazon account.
The European operating company of AmazonPay is Amazon Payments Europe s.c.a., 38 avenue J.F. Kennedy, L-1855 Luxembourg. If you already have an Amazon.de customer account, you can pay immediately using the payment method stored there – either by direct debit or credit card. Registration with your Amazon account is required for this purpose.
Further information and your order overview for payment via AmazonPay can be found at https://pays.amazon.de. When paying via Amazon Pay, all personal data communicated to or collected by Amazon Pay is processed primarily by Amazon Pays s.c.a. and secondarily by Amazon EU SARL, Amazon Services Europe SARL and Amazon Media EU SARL, all three located at 5, Rue Plaetis L 2338, Luxembourg. Further information on the processing of your data by Amazon in connection with AmazonPay can be found in the Amazon Pay privacy policy at: https://pay.amazon.com/de/help/201751600
Payment by credit card
You have the option of completing the payment by credit card.
If you have selected payment by credit card, payment data is transmitted to payment service providers for payment processing. All payment service providers comply with the requirements of the “Payment Card Industry (PCI) Data Security Standards” and have been certified by an independent PCI Qualified Security Assessor.
The following data is generally transmitted as part of payment by credit card:
- Purchase amount
- Date and time of purchase
- First name and surname
- Address
- Email address
- Credit card number
- Credit card expiry date
- Security code (CVC)
- IP address
- Telephone/mobile phone number
Payment data is transmitted to the following payment service provider:
- Adyen N.V., Simon Carmiggeltstraat 6-50, 1011 DJ Amsterdam, Netherlands
Further information on the privacy policies and on objection and removal options vis-à-vis the payment service provider can be found here: https://www.adyen.com/de_DE/legal/terms-and-conditions
Payment via Billie (B2B purchase on account)
We offer the option of purchasing on account via the payment service provider Billie GmbH.
The provider is Billie GmbH, Charlottenstraße 4, 10969 Berlin, Germany
If you select purchase on account via Billie, personal data is transmitted to Billie for the purpose of carrying out a credit check and processing the payment.
This includes in particular:
- First name and surname
- Billing and delivery address
- Company data (for B2B orders)
- Email address
- IP address
- Purchase amount
- Where applicable, date of birth
- Where applicable, other data required for payment processing
Billie carries out a risk assessment, including a credit check. Probability values (score values) may be calculated in this process. Processing takes place for the purpose of deciding on the establishment, performance or termination of the contractual relationship.
Further information on data processing by Billie can be found at:
https://www.billie.io/datenschutz/
Payment via PayPal
You have the option of processing the payment via the payment service provider PayPal.
The provider of this payment service is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg.
If you select PayPal as your payment method, the data required to process the payment is transmitted to PayPal.
This generally includes:
- First name and surname
- Billing and delivery address
- Email address
- IP address
- Purchase amount
- Date and time of purchase
- Payment method
- Where applicable, other data required for payment processing
PayPal reserves the right to carry out a credit check. Probability values (score values) may be calculated in this process. Further information on data processing by PayPal can be found at:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Payment in advance
If you have selected payment in advance, we do not process any data other than the data transmitted by your bank. This data is used solely to verify receipt of payment.
II.) Purpose of data processing
The transmission of payment data to payment service providers serves to process the payment, e.g. when you purchase a product and/or use a service.
III.) Legal basis for data processing
The legal basis for data processing is Art. 6 para. 1 sentence 1 lit. b GDPR, as processing the data is necessary to process the concluded purchase contract.
IV.) Storage period
All payment data and data relating to any chargebacks are stored only for as long as they are required for payment processing, the possible processing of returned direct debits and debt collection, and the prevention of misuse.
Payment data may also be stored beyond this period if and for as long as this is necessary to comply with statutory retention periods or to investigate a specific case of misuse.
Your personal data will be deleted upon expiry of the statutory retention obligations, i.e. after 10 years at the latest.
V.) Cessation of the legal basis
The payment service provider used remains entitled to process your payment data insofar as and for as long as this is necessary for payment processing in accordance with the contract. Additional statutory retention periods may also apply.
10. Shipping service providers
I.) Description and scope of data processing
If you order products or services on our website for which a shipping service provider is used for delivery, you will receive your order and shipping confirmation by email, as well as, depending on the respective shipping service provider, notification that your shipment has arrived and/or parcel notification and possible delivery options.
The data is transmitted to the following service providers:
- DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn
- General Logistics Systems Germany GmbH & Co. OHG, GLS Germany-Straße 1 - 7, DE-36286 Neuenstein
- United Parcel Service Deutschland S.à r.l. & Co. OHG, Görlitzer Straße 1, 41460 Neuss, Germany
The data transmitted generally consists of:
II.) Purpose of data processing
The purpose of processing personal data and transmitting address data to shipping service providers is to process the concluded purchase contract and deliver the goods.
III.) Legal basis for data processing
The legal basis for transmitting your address data (first name, surname, address) to the respective shipping service provider is Art. 6 para. 1 sentence 1 lit. b GDPR, as processing the data is necessary to process the concluded purchase contract.
IV.) Storage period
The transmitted data is deleted by the respective shipping service provider once the parcel has been delivered.
V.) Objection and removal options
The notification service provided by the shipping service provider can be cancelled by the data subject at any time. For this purpose, each email contains a corresponding opt-out link.
11. Email contact
I.) Description and scope of data processing
Our website allows you to contact us via the email address provided. In this case, the user’s personal data transmitted with the email is stored.
The data is used exclusively to process the conversation.
As part of the data processing, the data is transferred to the service provider: Zendesk Inc.
The data processing agreement with Zendesk includes so-called EU standard data protection clauses (Art. 46 para. 2 sentence 1 lit. c GDPR). These are classified as a suitable guarantee for protecting the transfer and processing of personal data outside the EU.
Further information on the processing of data by Zendesk can be found here: https://www.zendesk.de/company/agreements-and-terms/privacy-notice/
II.) Purpose of data processing
In the event of contact by email, this also constitutes the necessary legitimate interest in processing the data.
III.) Legal basis for data processing
The legal basis for processing the data transmitted when sending an email is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is to answer your email enquiry in the best possible manner. If the email contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6 para. 1 lit. b GDPR.
IV.) Storage period
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected and statutory retention periods no longer require its retention. For personal data sent by email, this is the case when the respective conversation with the user has ended. The conversation is considered ended when the circumstances indicate that the matter in question has been conclusively clarified.
V.) Possibility of objection
If the user contacts us by email, they may object to the storage of their personal data at any time. In such a case, the conversation cannot be continued.
Currently none, as contact is voluntary and purpose-related and is directed only at customers or prospective customers; deletion pursuant to the GDPR can be requested by email
All personal data stored in the course of contacting us will be deleted in this case.
12. Contact form
I.) Description and scope of data processing
Our website contains a contact form that can be used for electronic contact. If a user makes use of this option, the data entered in the input form is transmitted to us and stored.
At the time the message is sent, the following data is stored:
- Email address
- IP address of the accessing computer
- Date and time the form was submitted
- Order number & postcode if this concerns an existing order, for verification;
- Other data transmitted by the user as a message
Alternatively, you can contact us via the email address provided. In this case, the user’s personal data transmitted with the email is stored.
The data is used exclusively to process the conversation.
As part of the data processing, the data is transferred to the service provider: Zendesk Inc.
The data processing agreement with Zendesk includes so-called EU standard data protection clauses (Art. 46 para. 2 sentence 1 lit. c GDPR). These are classified as a suitable guarantee for protecting the transfer and processing of personal data outside the EU.
Further information on the processing of data by Zendesk can be found here: https://www.zendesk.de/company/agreements-and-terms/privacy-notice/
II.) Purpose of data processing
We process the personal data from the input form solely to process the contact request. In the event of contact by email, this also constitutes the necessary legitimate interest in processing the data.
The other personal data processed during the submission process serves to prevent misuse of the contact form and ensure the security of our information technology systems.
III.) Legal basis for data processing
The legal basis for processing the data transmitted when submitting a contact form is Art. 6 para. 1 sentence 1 lit. f GDPR. Our legitimate interest is to answer your enquiry submitted via the contact form in the best possible manner. If contact via the contact form is aimed at concluding a contract, the additional legal basis for processing is Art. 6 para. 1 sentence 1 lit. b GDPR.
IV.) Storage period
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected and statutory retention periods no longer require its retention. For the personal data from the contact form and data sent by email, this is the case when the respective conversation with the user has ended. The conversation is considered ended when the circumstances indicate that the matter in question has been conclusively clarified.
V.) Possibility of objection
The user may withdraw consent to the processing of personal data at any time. If the user contacts us by email, they may object to the storage of their personal data at any time. In such a case, the conversation cannot be continued.
All personal data stored in the course of contacting us will be deleted in this case.
13. Affiliate programmes
We also use the services of the following affiliate programmes:
Belboon GmbH: Weinmeisterstraße 12-14, 10178 Berlin
The controller has integrated components of Belboon on this website. Belboon is a German affiliate network offering affiliate marketing. If you click on an advertisement containing an affiliate link, Belboon places a cookie on your computer for conversion tracking. The cookies serve the purpose of correctly billing within the affiliate programme by recording the success of an advertising medium. The cookies recognise that you clicked on the advertisement and allow the origin of the order placed with the advertiser to be tracked. Belboon also uses so-called tracking pixels. These can be used to evaluate information such as visitor traffic on the pages.
The information generated by cookies and tracking pixels about the use of this website (including the IP address) and the delivery of advertising formats is transmitted to a Belboon server and stored there. Among other things, Belboon can recognise that the affiliate link on this website was clicked. Under certain circumstances, Belboon may pass this (anonymised) information on to contractual partners; however, data such as the IP address is not merged with other stored data.
Where legally required, we have obtained your consent pursuant to Art. 6 para. 1 lit. a GDPR for the processing of your data described above. You may withdraw your consent at any time with effect for the future. If you wish to block the analysis of user behaviour via cookies, you can set your browser to notify you when cookies are set and decide individually whether to accept them, or exclude the acceptance of cookies in certain cases or generally.
via an internet browser or other software programmes.
Further information on the processing of your personal data by Instagram and the corresponding objection options can be found here:
Belboon: https://www.belboon.com/de/ueber-uns/datenschutz/
Firstlead GmbH (Adcell): Rosenfelder Str. 15-16, 10315 Berlin.
The controller has integrated components of Adcell on this website. Adcell is a German affiliate network offering affiliate marketing. If you click on an advertisement containing an affiliate link, Adcell places a cookie on your computer for conversion tracking. The cookies serve the purpose of correctly billing within the affiliate programme by recording the success of an advertising medium. The cookies recognise that you clicked on the advertisement and allow the origin of the order placed with the advertiser to be tracked. Adcell also uses so-called tracking pixels. These can be used to evaluate information such as visitor traffic on the pages.
The information generated by cookies and tracking pixels about the use of this website (including the IP address) and the delivery of advertising formats is transmitted to an Adcell server and stored there. Among other things, Adcell can recognise that the affiliate link on this website was clicked. Under certain circumstances, Adcell may pass this (anonymised) information on to contractual partners; however, data such as the IP address is not merged with other stored data.
Where legally required, we have obtained your consent pursuant to Art. 6 para. 1 lit. a GDPR for the processing of your data described above. You may withdraw your consent at any time with effect for the future. If you wish to block the analysis of user behaviour via cookies, you can set your browser to notify you when cookies are set and decide individually whether to accept them, or exclude the acceptance of cookies in certain cases or generally.
Further information on the processing of your personal data by Adcell and the corresponding objection options can be found here: https://www.adcell.de/agb#sector_6
14. Review portal
Trustpilot review
We participate in the review process of the provider Trustpilot A/S, Pilestræde 58, 5, 1112 Copenhagen, Denmark.
Trustpilot gives users the opportunity to review our services. Users who have used our services are asked to consent to receiving a review request. If users have given the corresponding consent (by clicking a checkbox after completing the order), they receive a review request with a link to a review page. To ensure that users have actually used our services, we transmit to Trustpilot the data required for this purpose concerning the user and the service used (including their name, email address, order number and order date). This data is used solely to verify authenticity and contact the user.
The legal basis for processing the user’s data as part of the review process is consent pursuant to Art. 6 para. 1 lit. a GDPR.
To submit a review, it is possible to open a customer account with Trustpilot. In this case, Trustpilot’s terms and conditions and privacy notices apply. To maintain the neutrality and objectivity of the reviews, we have no direct influence on the reviews and cannot delete them ourselves. In this regard, we ask users to contact Trustpilot.
Further information on the processing of their data by Trustpilot and on their rights to object and other data subject rights can be found by users in Trustpilot’s privacy policy: https://de.legal.trustpilot.com/end-user-privacy-terms.
15. Email delivery
Mandrill
We use Mandrill by Mailchimp, provided by The Rocket Science Group, LLC, 512 Means Street, Suite 404 Atlanta, GA 30318 United States.
Mandrill is used when an order is completed to send you an order confirmation and, where applicable, payment reminders and other emails. In this context, we or our hosting provider process master data, contact data, content data, contract data, usage data, meta data and communication data of customers. The legal basis for data processing is Art. 6 para. 1 sentence 1 lit. b GDPR, as processing the data is necessary to process the concluded purchase contract.
The data processing agreement with Mandrill includes so-called EU standard data protection clauses (Art. 46 para. 2 sentence 1 lit. c GDPR). These are classified as a suitable guarantee for protecting the transfer and processing of personal data outside the EU.
Further information on Mandrill and data protection at Mandrill can be found here: http://mailchimp.com/legal/privacy/
16. Content Delivery Networks
I.) Description and scope of data processing
On our website, we use functions of the KeyCDN Content Delivery Network operated by proinity LLC, Reichenauweg 1, 8272 Ermatingen, Switzerland. A Content Delivery Network (CDN) is a network of regionally distributed servers connected via the internet, which is used to deliver content – particularly large media files such as videos. KeyCDN offers web optimisation and security services, which we use to improve the loading times of our website and protect it against misuse. When you access our website, a connection is established to the servers of proinity LLC in order to retrieve content, for example. This may result in personal data being stored and evaluated in server log files, particularly user activity (in particular which pages have been visited) and device and browser information (in particular the IP address and operating system).
Further information on the collection and storage of data by proinity LLC can be found here: https://www.keycdn.com/privacy
II.) Purpose of data processing
The functions are used to deliver and accelerate online applications and content.
III.) Legal basis for data processing
This data is collected on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website; server log files must be collected for this purpose.
IV.) Storage period
Your personal information is stored for as long as necessary to fulfil the purposes described in this privacy policy or as required by law.
V.) Objection and removal options
Information on objection and removal options vis-à-vis proinity LLC can be found at: https://www.keycdn.com/privacy
17. Use of Matomo
I.) Scope of the processing of personal data
We use the open-source tracking tool Matomo (https://matomo.org/) to analyse our users’ browsing behaviour. Matomo places a cookie on your computer. Matomo’s functions may be used to store and evaluate personal data, particularly user activity (in particular which pages have been visited and which elements have been clicked), device and browser information (in particular the IP address and operating system), data about the advertisements displayed (in particular which advertisements were displayed and whether the user clicked on them) and data from advertising partners (in particular pseudonymised user IDs). The software is configured so that IP addresses are not stored in full; instead, 2 bytes of the IP address are masked for anonymisation (e.g.: 192.168.xxx.xxx). This means that the truncated IP address can no longer be assigned to the accessing computer. The data is stored in our MySQL database; logs or report data are not sent to Matomo servers. Further information on data processing by Matomo can be found here: https://matomo.org/privacy-policy/
II.) Purpose of data processing
The processing of users’ personal data enables us to analyse our users’ browsing behaviour. By evaluating the data collected, we are able to compile information about the use of the individual components of our online presence. This helps us to continuously improve our online presence and its user-friendliness.
III.) Legal basis for processing personal data
The legal basis for processing users’ personal data is generally the user’s consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR.
IV.) Storage period
Your personal information is stored for as long as necessary to fulfil the purposes described in this privacy policy or as required by law, e.g. for tax and accounting purposes.
V.) Withdrawal and removal options
You have the right to withdraw your consent under data protection law at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent up to the time of withdrawal. You can prevent the collection and processing of your personal data by Matomo by preventing third-party cookies from being stored on your computer, using the "Do Not Track" function of a supported browser, disabling the execution of script code in your browser or installing a script blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com) in your browser. You can deactivate the processing of your personal data by Matomo using the following link: https://matomo.org/privacy-policy/ Further information on objection and removal options vis-à-vis Matomo can be found at: https://matomo.org/privacy-policy/
18. Use of Google Analytics (GA4)
I.) Scope of the processing of personal data
We use Google Analytics 4 ("GA4") to analyse user behaviour on our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data may be transferred to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Analytics uses cookies and processes information about the use of our website, in particular:
truncated IP address (IP anonymisation / IP is not stored permanently)
Date and time of access
Pages accessed / click paths
Referrer URL
Device and browser information
Approximate location data (region)
Events / conversions (e.g. completed purchase)
II.) Purpose of data processing
The processing enables us to analyse the use of our website and optimise the functionality, user guidance and economic efficiency of our online offering.
III.) Legal basis for processing personal data
The legal basis is your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR in conjunction with § 25 para. 1 TTDSG (setting/reading non-essential cookies). You provide consent via our consent manager and may withdraw it at any time with effect for the future.
IV.) Storage period
The storage period is based on the retention periods configured in Google Analytics. Data is deleted as soon as it is no longer required for the stated purposes. Further information on storage periods can be found in the settings of our consent manager or in the relevant information in the cookie settings.
V.) Withdrawal and removal options
You can withdraw your consent at any time via our consent manager. You can also prevent cookies from being stored by selecting the relevant setting in your browser software; however, please note that in this case you may not be able to use all functions of this website to their full extent.
Further information on data processing by Google can be found at: https://policies.google.com/privacy
19. Use of LiveChat
On our website, we use the live chat system of the provider LiveChat Inc., 1 International Pl, STE 1400 Boston, MA 02110 - 2619, USA, represented in the European Union by LiveChat Software SA, ul. Zwyci?ska 47, 53 - 033 Wroclaw, Poland, hereinafter referred to simply as "LiveChat". In our live chat, you have the opportunity to contact myfolie employees directly and ask questions in a real-time chat and receive answers. Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). If you do not agree to this processing, you can prevent the installation of cookies by selecting the appropriate settings in your internet browser. Details can be found above under the section "Privacy & Cookie Settings".
You can withdraw this consent here at any time; however, please note that in this case you may not be able to use all functions of this website to their full extent. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal.
Your personal data is also transferred to the USA. Since 10 July 2023, an adequacy decision, "EU-U.S. Data Privacy Framework", pursuant to Art. 45 III GDPR has existed for the USA. The European Commission has adopted the EU-US data protection framework and established in its decision that the United States ensures an adequate level of protection for personal data. However, the transfer of personal data to the United States applies only if the respective US data recipient is also certified under the EU-US Data Privacy Framework by the US Department of Commerce. A list of certified companies can be viewed at the following link: https://www.dataprivacyframework.gov/s/participant-search
Live Chat Inc. is certified under the Data Privacy Framework. Further information on the processing of your data by Trustpilot and on its rights to object and other data subject rights can be found in LiveChat’s privacy policy at https://www.livechatinc.com/legal/privacy-policy/#main
20. Use of Meta Pixel
I.) Scope of the processing of personal data
We use the Meta Pixel of Meta Platforms Inc., 1601 Willow Road, Menlo Park, CA 94025, USA, and its representative in the Union, Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, D2 Dublin, Ireland (hereinafter: Meta), on our online presence. It enables us to track users’ actions after they have viewed or clicked on a Meta advertisement. Personal data may thereby be stored and evaluated, particularly user activity (in particular which pages have been visited and which elements have been clicked), device and browser information (in particular the IP address and operating system), data about the advertisements displayed (in particular which advertisements were displayed and whether the user clicked on them) and data from advertising partners (in particular pseudonymised user IDs). This enables us to measure the effectiveness of Meta advertisements for statistical and market research purposes. Data may be transferred to Meta servers in the USA. The data collected in this way is anonymous to us, meaning that we do not see the personal data of individual users. However, this data is stored and processed by Meta. Meta may link this data to your Meta account and also use it for its own advertising purposes in accordance with Meta’s data usage policy. Further information on data processing by Meta can be found here: https://de-de.facebook.com/policy.php
II.) Purpose of data processing
The use of the Meta Pixel serves to analyse and optimise advertising measures.
III.) Legal basis for processing personal data
The legal basis for processing users’ personal data is generally the user’s consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR.
IV.) Storage period
Your personal information is stored for as long as necessary to fulfil the purposes described in this privacy policy or as required by law, e.g. for tax and accounting purposes.
Exercising your rights
You have the right to withdraw your consent under data protection law at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent up to the time of withdrawal. You can prevent the collection and processing of your personal data by Meta by preventing third-party cookies from being stored on your computer, using the "Do Not Track" function of a supported browser, disabling the execution of script code in your browser or installing a script blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com) in your browser. Further information on objection and removal options vis-à-vis Meta can be found at: https://de-de.facebook.com/policy.php
21. Plugins used
We use plugins for various purposes. The plugins used are listed below:
Microsoft Advertising (formerly Bing Ads)
Google Ads
- Provider: Google Ireland Ltd., Ireland (transfer to the USA possible)
- Purpose: Conversion tracking
- Legal basis: Art. 6 para. 1 sentence 1 lit. a GDPR (consent)
- Transfer to third countries: USA possible
- Privacy information:
https://policies.google.com/privacy?gl=DE&hl=de
Google Ads Remarketing
Google Tag Manager
Google Analytics (GA4)
- Provider: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (transfer to Google LLC, USA possible)
- Purpose: Web analysis / statistical evaluation of user behaviour / website optimisation
- Data processed (in particular): truncated IP address, device and browser information, referrer URL, page views, click behaviour, approximate location data, conversions
- Legal basis: Art. 6 para. 1 sentence 1 lit. a GDPR (consent) in conjunction with § 25 para. 1 TTDSG
- Transfer to third countries: USA possible
- Privacy information:
https://policies.google.com/privacy
https://business.safety.google/gdpr/
I.) Storage period
Your personal information is stored for as long as necessary to fulfil the purposes described in this privacy policy or as required by law.
II.) Transfers to third countries
When using plugins marked as involving transfers to third countries or the USA, personal data may be transferred to servers in third countries outside the EU, such as the USA. The legal basis for this transfer is consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR. The United States of America does not provide an adequate level of data protection on the basis of a decision by the European Union. The main risk of the transfer lies in the obligation of plugin providers, under certain circumstances, to make user data accessible to US authorities. We currently have data processing agreements with all providers containing standard contractual clauses, in order to make transfers to third countries as data-protection-friendly and secure as possible. We are currently seeking adjustments to the ruling of the CJEU dated 16 July 2020 (Schrems II, Case C-311/18), including additional security measures. A copy of the standard data protection clauses can be requested from us by sending an informal email.
III.) Possibility of withdrawal
You have the right to withdraw your consent under data protection law at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent up to the time of withdrawal.
You can prevent the respective providers from collecting and processing your personal data by preventing third-party cookies from being stored on your computer, using the "Do Not Track" function of a supported browser, disabling the execution of script code in your browser or installing a script blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com) in your browser.
IV.) Risk notice
Your personal data is also transferred to the USA. There is no adequacy decision pursuant to Art. 45 para. 3 GDPR for the USA. We would like to point out that transferring data without an adequacy decision entails certain risks, which we may inform you about as follows: US intelligence services use certain online identifiers (such as the IP address or unique identification numbers) as a starting point for monitoring individuals. In particular, it cannot be ruled out that these intelligence services have already collected information about you that could be used to link the data transferred here to you. Providers of electronic communications services headquartered in the USA are subject to monitoring by US intelligence services pursuant to 50 U.S. Code § 1881a ("FISA 702"). Accordingly, providers of electronic communications services headquartered in the USA are obliged to provide personal data to US authorities pursuant to 50 U.S. Code § 1881a, without you necessarily having access to legal remedies. Even encrypting the data in the data centres of the electronic communications service provider may not provide adequate protection, as an electronic communications service provider has a direct obligation with regard to imported data in its possession, custody or control to grant access to or disclose such data. This obligation may expressly also extend to the cryptographic keys without which the data cannot be read. The fact that this is not merely a “theoretical risk” is demonstrated by the CJEU judgment of 16 July 2020 (Case C 311/18, “Schrems II”). We have concluded guarantees with Google in the form of standard data protection clauses pursuant to Art. 46 para. 2 lit. c GDPR. A copy of the standard data protection clauses can be requested from us.