EN DE

Privacy Policy

GENERAL INFORMATION

The operators of this site take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy statement. As a rule, you can use our website without providing personal data. Any personal data (e.g. name, address or e-mail addresses) collected on our site is collected on a voluntary basis, insofar as this is possible. No personal data will be forwarded to any third parties without your express consent. You are expressly reminded that data transmission on the Internet (e.g. when communicating by e-mail) is not completely secure and cannot be completely protected against access by third parties.

COOKIES

SERVER LOG FILES

The website service provider automatically collects and stores information in so-called server log files, which your browser automatically sends to us. These are:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of the server request

This data cannot be assigned to specific persons. This data is not merged with other data sources. We reserve the right to check this data at a later date if there is reasonable evidence of unlawful usage.

Please note: You can configure your browser so that you are notified when cookies are set and can decide on a case-by-case basis whether to accept them, or you can disable the use of cookies for specific situations or in general. Each browser has a different method for managing cookie settings. This method is described in the help menu of any browser, which tells you how to change your cookie settings. This can be found under the following links for the respective browsers:

Internet Explorer:
https://support.microsoft.com/en-us/help/17442/windows-internet-explorer-delete-manage-cookies

Firefox:
https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences

Chrome:
https://support.google.com/chrome/answer/95647?hl=en-GB&hlrm=en

Safari:
https://support.apple.com/kb/ph21411?locale=en_US

Opera:
https://help.opera.com/en/latest/web-preferences/#cookies

Please note: if cookies are not accepted, the functionality of our website may be limited.

Making Contact

When you contact us (e.g. via contact form or e-mail), your personal data is collected. The data that is collected from a contact form is evident from the respective contact form. The data obtained from these forms is stored and used only for the purposes of responding to your query, contacting you and for the related technical administration. The legal basis for the processing of personal data is our legitimate interest in responding to your query, in acc. with Art. 6 Para. 1(f) of the GDPR. If you have contacted us with the aim of concluding a contract, the additional legal basis for processing the data is as per Art. 6 Para. 1(b) of the GDPR. Once processing of your query is complete, your data is deleted; this occurs if circumstances indicate that the issue concerned has been resolved and if there are no legal obligations to store the data.

DATA PROCESSING FOR ORDER HANDLING

To handle your order, we work together with the following service provider(s), who support us wholly or partially in the execution of concluded contracts. Certain personal data is transferred to these service providers in accordance with the following information.

The personal data collected by us will be passed on to the transport company commissioned with the delivery within the scope of contract processing, if this is necessary for the delivery of the goods. We will pass on your payment data to the commissioned credit institution within the framework of payment processing, if this is necessary for the processing of payments. If payment service providers are used, we explicitly inform you of this below. The legal basis for the transfer of data is Art. 6 Para. 1(b) of the GDPR.

USE OF PAYMENT SERVICE PROVIDERS

PAYPAL

When paying via PayPal, credit card via PayPal, direct debit via PayPal or – if offered - "purchase on account" or "payment in instalments" via PayPal, we will pass on your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal"), within the framework of payment processing. The transfer of data is in accordance with Art. 6 Para. 1(b) of the GDPR and only if this is necessary for payment processing.

PayPal reserves the right to carry out a credit check for the following payment methods: Credit card via PayPal, direct debit via PayPal or – if offered – "purchase on account" or "payment in instalments" via PayPal. For this purpose, your payment details may be passed on to credit agencies, where necessary, on the basis of the legitimate interests of PayPal in determining solvency, pursuant to Art. 6 Para. 1(f) of the GDPR. PayPal uses the result of the credit assessment in relation to the statistical probability of non-payment for the purpose of deciding on the provision of the respective payment method. The credit report can contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on recognised scientific, mathematical-statistical methods. The calculation of the score values includes, but is not limited to, address data. For further information on data protection law, including the credit agencies used, please refer to PayPal's privacy statement at:

https://www.paypal.com/de/webapps/mpp/ua/privacy-full

You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.

AMAZON PAY

When paying via Amazon Pay, we pass on your payment details to Amazon Payments Europe s.c.a. and, secondarily, Amazon EU SARL, Amazon Services Europe SARL and Amazon Media EU SARL, all three of which are located at 5, Rue Plaetis L 2338 Luxembourg (hereinafter referred to as "Amazon Payments"), within the framework of payment processing.

Amazon Payments reserves the right to carry out a credit report. Amazon Payments uses the result of the credit assessment in relation to the statistical probability of non-payment for the purpose of deciding on the provision of the respective payment method. The credit report may contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on recognised scientific, mathematical-statistical methods. The calculation of the score values includes address data, among other things.

Furthermore, Amazon Payments shall be entitled to pass on your data to unnamed third parties (banks, e-service provides, service partners, but also auditors, analytics services, credit agencies, marketing partners, cloud service providers, retargeting providers, associated companies), among others.

For further information on data protection law, including the credit agencies used, please refer to Amazon Payments' data privacy statement at:

https://pay.amazon.com/de/help/201751600

The legal basis for this is Article 6(1b) GDPR.

Ratepay

If you have opted for the Ratepay prepayment, Ratepay invoice, Ratepay SEPA direct debit or Ratepay purchase in instalments payment methods as your payment option, you will be prompted to enter your personal details during the ordering process (first name and surname, street, house number, post code, town, date of birth, e-mail address, phone number and, for SEPA direct debit, the specified bank details). This data will be forwarded to Ratepay GmbH, Franklinstraße 28-29, 10587 Berlin ("Ratepay") for the purpose of a risk assessment. Based on the personal details you provide, as well as other data (such as shopping cart, invoice amount, order history, payment experiences), Ratepay will check whether your selected payment option can be granted with regard to payment and/or receivables default risks. When processing your data for risk analysis, we protect you against any possible over-indebtedness, fraudulent use of your personal data as well as ourselves against a risk of default. This data processing is carried out in accordance with Article 6(1)(f) GDPR based on the specified legitimate interests.

For the purposes of the risk assessment, a credit report from credit agencies can also be requested. For this purpose, your personal data may be sent to a credit agency in accordance with Article 6(1)(f) GDPR. You can find a list of the credit agencies used by Ratepay here: https://www.ratepay.com/legal-payment-creditagencies/

The credit report may contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on recognised scientific, mathematical-statistical methods. The calculation of the score values includes, but is not limited to, address data. This process is in the interest of all participants in the economy, the avoidance of default in payment and the over-indebtedness of consumers and debtors and is therefore based on Article 6(1)(f) GDPR. You can object to this processing of your data at any time by notifying the data controller or Ratepay. However, Ratepay may still be entitled to process your personal data if this is necessary for contractual payment processing.

Further details on the Ratepay's privacy policy can be found in the Ratepay terms and conditions of payment (https://www.ratepay.com/legal-payment-terms/) as well as the Ratepay privacy policy (https://www.ratepay.com/legal-payment-dataprivacy/).

FACEBOOK PLUG-INS (LIKE BUTTON)

Our website uses plug-ins from the social network Facebook, which is operated by Facebook Inc., 1 Hacker Way, Menlo Park, California 94025, USA. The Facebook plug-ins are identified by the Facebook logo or the "Like" button on our website. An overview of the Facebook plug-ins can be found at:

https://developers.facebook.com/docs/plugins/

When you visit one of our website pages, the plug-in establishes a direct connection between your browser and the Facebook server. This will inform Facebook that your IP address has visited our site. If you click the Facebook "Like" button while logged into your Facebook account, you can link the contents of our website on your Facebook profile. Facebook can then associate visits to our website with your user account. We would like to point out that, as the provider of these pages, we are not aware of the content of the transmitted data or its use by Facebook. For more information, see Facebook's privacy policy at https://de-de.facebook.com/policy.php.

If you do not want Facebook to be able to link visits to our website with your Facebook user account, please log out of your Facebook user account.

TWITTER

Our website contains functions of the Twitter service. These functions are provided by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. By using Twitter and the "Retweet" function, the websites you visit will be linked to your Twitter account and made known to other users. Data is also transferred to Twitter. We would like to point out that, as the provider of this website, we are not aware of the content of the transmitted data or its use by Twitter.

For more information, see the Twitter privacy policy at https://twitter.com/privacy.

You can change your Twitter privacy settings in your account settings at:

https://twitter.com/privacy

https://twitter.com/account/settings

INSTAGRAM

Our website contains functions of the Instagram service. These functions are provided by Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA. If you are logged in to your Instagram account, you can click the Instagram button to link the content of our pages with your Instagram profile. Instagram can then associate visits to our website with your user account. We would like to point out that, as the provider of this website, we are not aware of the content of the transmitted data or its use by Instagram.

For more information, see the Instagram privacy policy:

https://instagram.com/about/legal/privacy/

NOTE ON THE INTEGRATION OF VIDEOS

Our website uses videos. To embed our videos, we use external third party suppliers. For technical reasons, embedding videos results in connection to the server of the provider.

YOUTUBE

Our website uses plug-ins of the Google-operated YouTube website. The operator of the website is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you visit one of our pages that has a YouTube plug-in, a connection to the YouTube servers is established.

The YouTube server is informed about which of our pages you visited. If you are logged in to your YouTube account, you allow YouTube to assign your surfing behaviour directly to your personal profile.

You can prevent this by logging out of your YouTube account.

For more information about the handling of user data, see the YouTube privacy policy: https://policies.google.com/privacy

https://policies.google.com/privacy

GOOGLE ANALYTICS

This website uses functions of the web analysis service Google Analytics. This service is provided by Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA.

Google Analytics uses "cookies". These are text files that are stored on your computer to help the website analyse how users use the site. The information generated by the cookie about your usage of this website is generally transferred to a Google server in the USA and stored there.

IP ANONYMISATION

We have activated the IP anonymisation function on this website. In this way, your IP address will be shortened by Google within the Member States of the European Union or in other States party to the Agreement on the European Economic Area, prior to transmission to the USA. Only in exceptional cases is your full IP address transmitted to a Google server in the United States and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports about the website activities for the website operators and to provide other services associated with website use and Internet use. The IP address that is transferred from your browser as part of Google Analytics will not be combined with other Google data.

BROWSER PLUG-IN

You can prevent the storage of cookies with a corresponding setting on your browser software; however, please be aware that with this setting you may not be able to fully use all functions of this website. Furthermore, you can prevent Google from collecting data generated by the cookie and your use of our website (inc. your IP address), as well as the processing of this data by Google, by downloading and installing the browser plug-in found here:

https://tools.google.com/dlpage/gaoptout?hl=en

OBJECTING TO DATA COLLECTION

You can prevent Google Analytics from collecting your data by clicking the following link. This sets an opt-out cookie, which will prevent data from being collected during future visits to this website. Deactivate Google Analytics.

Google Analytics Deactivation

For more information on how Google Analytics handles user data, see Google's privacy policy:

https://support.google.com/analytics/answer/6004245?hl=en

DOUBLECLICK BY GOOGLE

This website uses the online marketing tool DoubleClick by Google, operated by Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("DoubleClick").

DoubleClick uses cookies to display user-relevant adverts, improve campaign performance reporting or to prevent the user from seeing the same adverts repeatedly. A cookie ID enables Google to determine which adverts are placed on which browser and can thereby prevent these adverts from being shown repeatedly. Data is processed on the basis of our legitimate interest in the optimum marketing of our website, pursuant to Art. 6 Para. 1(f) of the GDPR.

Cookie IDs also allow DoubleClick to log so-called conversions related to ad requests. This would be the case if, for instance, a user sees a DoubleClick advert and then, with the same browser, visits the advertiser's website and makes a purchase there. According to Google, DoubleClick cookies do not contain any personal information.

As a result of the marketing tool used, your browser automatically establishes a direct connection with the Google server. We have no influence on the scope and further use of the data that Google collects through the use of this tool and therefore inform you according to the state of our knowledge: By integrating DoubleClick, Google receives the information that you have accessed the relevant part of our website or clicked on one of our adverts. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google or you are not logged in, there is still a possibility that the provider may discover and store your IP address.

If you wish to opt out of this tracking process, you can disable cookies for conversion tracking by configuring your browser so that cookies from the domain www.googleadservices.com are blocked, although this setting is deleted if you delete your cookies. Alternatively, you can contact the Digital Advertising Alliance at www.aboutads.info to find out how to set cookies and make the relevant adjustments. Finally, you can configure your browser so that you are notified when cookies are set and can decide on a case-by-case basis whether to accept them, or you can disable the use of cookies for specific situations or in general. If cookies are not accepted, the functionality of our website may be limited.

Google LLC based in the USA is certified for the US-European data protection agreement "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU.

For more information about DoubleClick by Google's privacy policy, please visit:

http://www.google.com/policies/privacy/

FACEBOOK CUSTOM AUDIENCE VIA THE PIXEL PROCESS

This website uses "Facebook Pixel" managed by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook"). Provided express consent has been given, the behaviour of a user can be tracked after they have seen or clicked on a Facebook ad. This process is designed to measure the effectiveness of Facebook ads for statistical and market research purposes and may help to optimise future advertising activities.

The data collected in this way is anonymous to us so we cannot identity the user. However, this data is stored and processed by Facebook, who may make a connection with the respective user profile and may also use the data for its own promotional purposes, in accordance with the Facebook data usage policy (https://www.facebook.com/about/privacy/). You can allow Facebook and its partners to place ads on and off Facebook. A cookie may also be stored on your computer for these purposes. These processing operations may be carried out only with your express consent, in accordance with Art. 6 Para. 1(a) of the GDPR.

Consent to the use of Facebook Pixel can only be given by users over the age of 13. If you are under 13, please seek permission from your parent or guardian.

Facebook Inc., based in the USA is certified for the US-European data protection agreement "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU.

To disable the use of cookies on your computer, you can configure your browser so that no more cookies can be placed on your computer in future and already existing cookies will be deleted. However, disabling all cookies may mean that several functions on the pages of our website will no longer work.

You can also disable the use of cookies by third parties such as Facebook on the following Digital Advertising Alliance website:

https://optout.aboutads.info

RIGHTS OF THE DATA SUBJECT

The applicable data privacy laws grant you extensive rights (right of access and right to intervene) vis-à-vis the person responsible for the processing of your personal data. Please find the relevant information below:

  • Right of access, pursuant to Art. 15 of the GDPR: In particular, you have the right of access to your personal data that we have processed and the following information: The purposes of the processing; the categories of personal data concerned; the recipients or categories of recipient to whom the data have been or may be disclosed, the envisaged data storage period or the criteria used to determine that period; the existence of the right to request rectification or erasure of personal data, or restriction of processing, or to object to such processing; the right to lodge a complaint with a supervisory authority; where the personal data are not collected from the data subject, any available information as to their source; the existence of automated decision-making, including profiling and where necessary meaningful information about the logic involved as well as the significance and the envisaged consequences of such processing for the data subject; and your right to be informed of the appropriate safeguards pursuant to Art. 46 of the GDPR relating to the transfer of data to third countries;
  • Right to rectification, pursuant to Art. 16 of the GDPR: You have a right to obtain without undue delay the rectification of inaccurate personal data and/or to the completion of incomplete personal data stored with us;
  • Right to erasure, pursuant to Art. 17 of the GDPR: You have the right to obtain erasure of your personal data provided that the conditions of Art. 17 Para. 1 of the GDPR are met. However, this right shall not apply to the extent that processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims;
  • Right to restriction of processing, pursuant to Art. 18 of the GDPR: You have the right to obtain restriction of processing of your personal data, as long as the contested accuracy of your data is checked; if you oppose the erasure of your personal data due to unlawful processing and request the restriction of their processing instead; if we no longer need the personal data for the purposes of the processing but you need your data for the establishment, exercise or defence of legal claims; or if you have objected to processing pending the verification of whether our legitimate grounds override yours;
  • Right of erasure, pursuant to Art. 19 of the GDPR: If you have asserted against the controller the right to rectification, erasure or restriction of processing, the latter is obligated to notify all recipients to whom the personal data concerning you were disclosed of this rectification or erasure of the data or restriction of processing unless this proves to be impossible or involves a disproportionate effort. You have the right to be notified of these recipients.
  • Right to data portability, pursuant to Art. 20 of the GDPR: You have the right to receive your personal data that you provided us with in a structured, commonly used and machine-readable format or to transmit those data to another controller, where this is technically feasible;
  • Right to revocation of consent, pursuant to Art. 7 Para. 3 of the GDPR: You have the right to withdraw your consent to the processing of data at any time with effect for the future. If consent is withdrawn, we will delete the relevant data immediately, unless it can be further processed on another legal ground. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal;
  • Right to object, pursuant to Art. 77 of the GDPR: If you consider that the processing of the personal data concerning you infringes the GDPR, you have the right – without prejudice to any other administrative or legal remedy – to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement.

SSL ENCRYPTION

This site uses SSL encryption for security reasons and to protect the transmission of confidential content, such as the inquiries you send to us as the site operator. You can recognise an encrypted connection in your browser's address line when it changes from "http://" to "https://" and the lock icon is displayed in your browser's address bar. If SSL encryption is activated, the data you transfer to us cannot be read by third parties.

ONLINE SURVEYS

We will conduct surveys with our customers on various topics at irregular intervals. These surveys will be carried out online via the Netigate programme. You will receive an invitation via e-mail or within the newsletter to take part in the survey on a voluntary basis. By confirming the data privacy statements, you are providing us with your consent to collect, process and use your personal data in accordance with Art. 6(1a) GDPR. Netigate will save this data and evaluate it on behalf of Interstuhl. To this end, we have entered into a commissioned data processing agreement with Netigate which prohibits the forwarding of data to third parties.

The data collected within these surveys will be used for internal purposes only (optimisation of offers, processes and services). Participation in the survey and provision of consent regarding data privacy is voluntary and can be revoked at any time by sending an appropriate message to the person(s) responsible listed in the legal notice. Once you have revoked your consent, your personal data will be deleted by Netigate, unless you have expressly given consent to further use of your data or we reserve the right to further use your data in the scope and manner permitted by law.

RIGHT TO ACCESS, ERASURE, BLOCKING

You have the right at any time to free information about your stored data, its origin and recipients and the purpose of the processing, as well as a right to rectification, blocking or erasure of these data. For further details on this and on the issue of personal data, please contact us at any time via the address given in the legal notice (Imprint).

If you have any questions that could not be answered by our privacy statement, or if you have questions about the processing of your personal data, please contact our data privacy officer, who is also available to help with information requests, comments and suggestions and complaints.

Data privacy officer:

Steffen Wacker

dataprivacy@interstuhl.com

OBJECTION TO PROMOTIONAL MAIL

The use of contact details, published as part of the obligation to provide a legal notice (Impressum), by third parties for the sending of unsolicited advertisements and information, is hereby expressly forbidden. The operators of the website reserve the right to legal action in the event of unsolicited advertisements, such as spam e-mail.

IMPLEMENTATION OF CREDIT ASSESSMENTS

If we have to provide services in advance (e.g. delivery on account), we reserve the right to perform a credit assessment based on mathematical-statistical methods in order to maintain our legitimate interest in determining the ability of our customers to pay. We will send the personal data required for a credit assessment to the following service providers in accordance with Article 6(1)(f) GDPR:

SCHUFA Holding AG
Kormoranweg 5
65201 Wiesbaden

The credit report may contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on recognised scientific, mathematical-statistical methods. The calculation of the score values includes, but is not limited to, address data. We will use the result of the credit assessment in relation to the statistical probability of default in payment for the purposes of deciding on the foundation, implementation or termination of a contractual relationship.

You can object to this processing of your data at any time by notifying the data controller or the above-mentioned credit agency. However, we may still be entitled to process your personal data if this is necessary for contractual payment processing.

USE OF RATING AND TEST SEAL GRAPHICS

To display our Trusted Shops trustmark and to offer Trusted Shops membership to buyers after placing an order, the Trusted Shops Trustbadge is integrated into this website.
In the context of a balance of interests, this serves to protect our prevailing legitimate interests in the optimal marketing of our offering, Article 6(1)(f) GDPR. The Trustbadge and the services acquired with it are an offering by Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne.

When the Trustbadge is accessed, the web server automatically saves a so-called server log file that contains e.g. your IP address, date and time of access, transferred data volume and the requesting provider (access data) and documents the access. This access data is not evaluated and is automatically overwritten at the latest seven days after the end of your visit to the website.
Further personal data is only transferred to Trusted Shops if you decide to use Trusted Shops products after completing an order or have already registered for their use. In this case, the contractual agreement between you and Trusted Shops applies.