Privacy Policy
We only process personal data (hereinafter referred to as “data”) to the extent necessary and for the purpose of providing a functional and user-friendly website, including its content and the services offered there.
According to Art. 4(1) of Regulation (EU) 2016/679, i.e. the General Data Protection Regulation (hereinafter referred to as “GDPR”), “processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
With the following privacy policy, we inform you in particular about the type, scope, purpose, duration, and legal basis of the processing of personal data, insofar as we either alone or jointly with others decide on the purposes and means of processing. In addition, we inform you below about the third-party components we use for optimization purposes and to increase the quality of use, insofar as third parties process data on their own responsibility.
Our privacy policy is structured as follows:
I. Information about us as the controller
II. Rights of users and data subjects
III. Information on data processing
I. Information about us as the controller
The controller of this website in terms of data protection law is:
Corinna Behling
Corinna Behling
Am Alefskamp 79
47198 Duisburg
Phone: 015735380215
Email: corinna.behiing@flow-entfalten.com
The provider's data protection officer is:
Corinna Behling
Phone: 015735380215
Email: corinna.behling@flow-entfalten.com
II. Rights of users and data subjects
With regard to the data processing described in more detail below, users and data subjects have the right
- to confirmation as to whether data concerning them is being processed, to information about the data being processed, to further information about data processing, and to copies of the data (see also Art. 15 GDPR);
- to have inaccurate or incomplete data corrected or completed (see also Art. 16 GDPR);
- to the immediate deletion of data concerning them (see also Art. 17 GDPR), or, alternatively, if further processing is necessary in accordance with Art. 17 (3) GDPR, to the restriction of processing in accordance with Art. 18 GDPR;
- to receive the data concerning them and provided by them and to transfer this data to other providers/controllers (see also Art. 20 GDPR);
- to lodge a complaint with the supervisory authority if they believe that the data concerning them is being processed by the provider in violation of data protection regulations (see also Art. 77 GDPR).
In addition, the provider is obliged to inform all recipients to whom data has been disclosed by the provider of any correction or deletion of data or restriction of processing that takes place on the basis of Articles 16, 17(1), and 18 GDPR. However, this obligation does not apply if such notification is impossible or involves disproportionate effort. Notwithstanding this, the user has a right to information about these recipients.
Likewise, users and data subjects have the right under Art. 21 GDPR to object to the future processing of data concerning them, provided that the data is processed by the provider in accordance with Art. 6 (1) lit. f) GDPR. In particular, an objection to data processing for the purpose of direct marketing is permissible.
III. Information on data processing
Your data processed when using our website will be deleted or blocked as soon as the purpose of storage no longer applies, the deletion of the data does not conflict with any legal retention obligations, and no other information on individual processing procedures is provided below.
Cookies
a) Session cookies
We use cookies on our website. Cookies are small text files or other storage technologies that are stored on your device by the Internet browser you use. These cookies process certain information about you, such as your browser or location data or your IP address, to an individual extent.
This processing makes our website more user-friendly, effective, and secure, as it enables, for example, the display of our website in different languages or the provision of a shopping cart function.
The legal basis for this processing is Art. 6 (1) (b) GDPR, insofar as these cookies process data for the purpose of initiating or executing a contract.
If the processing does not serve the purpose of contract initiation or contract processing, our legitimate interest lies in improving the functionality of our website. The legal basis is then Art. 6 (1) lit. f) GDPR.
These session cookies are deleted when you close your internet browser.
b) Third-party cookies
Our website may also use cookies from partner companies with whom we collaborate for the purposes of advertising, analysis, or the functionality of our website.
For details on this, in particular on the purposes and legal basis for the processing of such third-party cookies, please refer to the following information.
c) Removal option
You can prevent or restrict the installation of cookies by adjusting your Internet browser settings. You can also delete cookies that have already been stored at any time. However, the steps and measures required for this depend on the specific Internet browser you are using. If you have any questions, please use the help function or documentation of your Internet browser or contact its manufacturer or support. However, the processing of so-called Flash cookies cannot be prevented via the browser settings. Instead, you must change the settings of your Flash player. The steps and measures required for this also depend on the specific Flash player you are using. If you have any questions, please use the help function or documentation of your Flash player or contact the manufacturer or user support.
If you prevent or restrict the installation of cookies, however, this may mean that not all functions of our website can be used to their full extent.
Contact requests / contact options
If you contact us via the contact form or email, the data you provide will be used to process your request. The provision of this data is necessary for processing and responding to your request—without it, we cannot respond to your request or can only respond to it to a limited extent.
The legal basis for this processing is Art. 6 (1) lit. b) GDPR.
Your data will be deleted once your request has been answered and there are no legal retention obligations that prevent deletion, such as in the case of any subsequent contract processing.
Customer account / registration function
If you create a customer account with us via our website, we will use the data you entered during registration (e.g. your name, address, or email address) exclusively for pre-contractual services, for the fulfillment of the contract, or for the purpose of customer care (e.g., to provide you with an overview of your previous orders with us or to offer you the so-called memo function). At the same time, we will then store the IP address and the date and time of your registration. This data will not, of course, be passed on to third parties.
As part of the further registration process, your consent to this processing will be obtained and reference will be made to this privacy policy. The data we collect in this process will be used exclusively for the provision of the customer account.
If you consent to this processing, Art. 6 (1) lit. a) GDPR is the legal basis for the processing.
If the opening of the customer account also serves pre-contractual measures or the fulfillment of the contract, the legal basis for this processing is also Art. 6 (1) lit. b) GDPR.
You can revoke your consent to the opening and maintenance of the customer account at any time with future effect in accordance with Art. 7 (3) GDPR. To do so, you simply need to inform us of your revocation.
The data collected in this regard will be deleted as soon as processing is no longer necessary. However, we must observe tax and commercial law retention periods.
Newsletter
If you register for our free newsletter, the data requested from you for this purpose, i.e., your email address and—optionally—your name and address, will be transmitted to us. At the same time, we store the IP address of the Internet connection from which you access our website, as well as the date and time of your registration. As part of the further registration process, we will obtain your consent to send you the newsletter, describe the content in detail, and refer you to this privacy policy. We use the data collected in this process exclusively for sending the newsletter—it will therefore not be passed on to third parties.
The legal basis for this is Art. 6 (1) (a) GDPR.
You can revoke your consent to receive the newsletter at any time with future effect in accordance with Art. 7 (3) GDPR. To do so, simply notify us of your revocation or click on the unsubscribe link included in every newsletter.
Server data
For technical reasons, in particular to ensure a secure and stable website, data is transmitted to us or our web space provider by your internet browser. These so-called server log files collect, among other things, the type and version of your Internet browser, the operating system, the website from which you accessed our website (referrer URL), the website(s) of our website that you visit, the date and time of each access, and the IP address of the Internet connection from which our website is used.
The data collected in this way is stored temporarily, but not together with other data about you.
This storage is based on the legal basis of Art. 6 (1) lit. f) GDPR. Our legitimate interest lies in the improvement, stability, functionality, and security of our website.
The data will be deleted after seven days at the latest, unless further storage is necessary for evidentiary purposes. Otherwise, the data will be excluded from deletion in whole or in part until an incident has been finally clarified.
Contract processing
The data you provide to use our goods and/or services will be processed by us for the purpose of contract processing and is necessary in this respect. Contract conclusion and contract processing are not possible without the provision of your data.
The legal basis for processing is Art. 6 (1) lit. b) GDPR.
We delete the data once the contract has been fully processed, but must comply with the retention periods under tax and commercial law.
Within the scope of contract processing, we pass on your data to the transport company commissioned with the delivery of goods or to the financial service provider, insofar as the transfer is necessary for the delivery of goods or for payment purposes.
The legal basis for the transfer of data is then Art. 6 (1) lit. b) GDPR.
We operate a company presence on the Instagram platform to promote our products and services and to communicate with interested parties or customers.
We are jointly responsible for this social media platform together with Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
Instagram's data protection officer can be contacted via a contact form:
https://www.facebook.com/help/contact/540977946302970
We have regulated our joint responsibility in an agreement regarding the respective obligations within the meaning of the GDPR. This agreement, which sets out the mutual obligations, is available at the following link:
https://www.facebook.com/legal/terms/page_controller_addendum
The legal basis for the resulting processing of personal data, which is reproduced below, is Art. 6 (1) lit. f GDPR. Our legitimate interest lies in the analysis, communication, sales, and promotion of our products and services.
The legal basis may also be the user's consent to the platform operator in accordance with Art. 6 (1) (a) GDPR. The user may revoke this consent at any time for the future by notifying the platform operator in accordance with Art. 7 (3) GDPR.
When you visit our online presence on the Instagram platform, Meta Platforms Ireland Limited, as the operator of the platform in the EU, processes user data (e.g., personal information, IP address, etc.).
This user data is used to provide statistical information about the use of our company presence on Instagram. Meta Platforms Ireland Limited uses this data for market research and advertising purposes, as well as to create user profiles. Based on these profiles, Meta Platforms Ireland Limited can, for example, advertise to users within and outside of Instagram based on their interests. If the user is logged into their Instagram account at the time of access, Meta Platforms Ireland Limited can also link the data to the respective user account.
If the user contacts us via Instagram, the personal data entered by the user on this occasion will be used to process the request. The user's data will be deleted by us once the user's request has been answered and there are no legal retention obligations, such as in the case of subsequent contract processing.
Meta Platforms Ireland Limited may also set cookies to process the data.
If the user does not agree to this processing, they can prevent the installation of cookies by adjusting their browser settings accordingly. Cookies that have already been stored can also be deleted at any time. The settings for this depend on the respective browser. In the case of Flash cookies, processing cannot be prevented via the browser settings, but by adjusting the Flash Player settings accordingly. If the user prevents or restricts the installation of cookies, this may mean that not all functions of Facebook can be used to their full extent.
Further information on processing activities, how to prevent them, and how to delete the data processed by Instagram can be found in Instagram's data policy:
https://help.instagram.com/519522125107875
It cannot be ruled out that Meta Platforms Ireland Limited may also process data via Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA.
We maintain an online presence on LinkedIn to present our company and our services and to communicate with customers/prospective customers. LinkedIn is a service provided by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, a subsidiary of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.
In this regard, we would like to point out that there is a possibility that user data may be processed outside the European Union, in particular in the USA. This may pose increased risks for users in that, for example, subsequent access to user data may be more difficult. We also have no access to this user data. Access is exclusively available to LinkedIn.
LinkedIn's privacy policy can be found at
https://www.linkedin.com/legal/privacy-policy.
Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
Privacy policy: https://www.facebook.com/policy.php.
Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
Privacy policy: https://help.instagram.com/519522125107875
LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, a subsidiary of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085 USA.
Privacy policy: https://www.linkedin.com/legal/privacy-policy
Pinterest Inc., 651 Brannan Street, San Francisco, CA, 94107, USA.
Privacy policy: https://policy.pinterest.com/de/privacy-policy
X
Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland. Privacy policy: https://x.com/de/privacy
YouTube
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, a subsidiary of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA
Privacy policy: https://policies.google.com/privacy
“Facebook” social plug-in
We use the plug-in from the social network Facebook on our website. Facebook is an internet service provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
If you have given your consent to this processing, the legal basis is Art. 6 (1) (a) GDPR. The legal basis may also be Art. 6 (1) (f) GDPR. Our legitimate interest lies in improving the quality of our website.
Further information about the possible plug-ins and their respective functions is available from Facebook at
https://developers.facebook.com/docs/plugins/
.
If the plug-in is stored on one of the pages of our website that you visit, your Internet browser downloads a representation of the plug-in from Facebook's servers in the USA. For technical reasons, it is necessary for Facebook to process your IP address. In addition, the date and time of your visit to our website are also recorded.
If you are logged into Facebook while visiting one of our websites equipped with the plug-in, Facebook will recognize the information collected by the plug-in about your specific visit. Facebook may assign the information collected in this way to your personal user account there. If, for example, you use the Facebook “Like” button, this information will be stored in your Facebook user account and may be published on the Facebook platform. If you want to prevent this, you must either log out of Facebook before visiting our website or use an add-on for your Internet browser to prevent the Facebook plug-in from being loaded.
Further information about the collection and use of data, as well as your rights and protection options in this regard, is available in Facebook's privacy policy at
https://www.facebook.com/policy.php
.
“Shariff” social media buttons
We use plug-ins from the following social networks on our website. We use the “Shariff” plug-in to integrate these plug-ins.
The legal basis for this is Art. 6 (1) (f) GDPR. Our legitimate interest lies in improving the quality of our website.
Shariff is an open source program developed by c't and heise. By integrating this plug-in, linked graphics prevent the social network plug-ins specified below from automatically connecting to the respective server of the social network plug-in when you visit our website(s) on which the respective social network plug-in is integrated. Only when you click on one of these linked graphics will you be redirected to the service of the respective social network. Only then will the respective social network collect information about the usage process. This information includes, for example, your IP address, the date and time, and the page of our website that you visited.
If you are logged into one of the social network services while visiting one of our websites equipped with the corresponding plug-in, the provider of the respective social network may be able to recognize the information collected about your specific visit and assign it to your personal user account or publish it. If, for example, you use the “share” button of the respective social network, this information may be stored in your user account there and published via the platform of the respective social network provider. If you want to prevent this, you must either log out of the respective social network before clicking on the graphic or make the appropriate settings in your user account of the social network.
Further information about “Shariff” is available from heise at
http://www.heise.de/ct/artikel/Shariff-Social-Media-Buttons-mit-Datenschutz-2467514.html
.
The following social networks are integrated into our website:
Facebook from Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
Privacy information can be found at https://www.facebook.com/policy.php
Twitter from Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA.
Privacy information can be found at https://twitter.com/privacy
“X” social plug-in
We use the plug-in from the social network Twitter on our website. Twitter is an internet service provided by Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA, hereinafter referred to as “Twitter”.
If you have given your consent to this processing, the legal basis is Art. 6 (1) (a) GDPR. The legal basis may also be Art. 6 (1) (f) GDPR. Our legitimate interest lies in improving the quality of our website.
If the plug-in is stored on one of the pages of our website that you visit, your internet browser downloads a representation of the plug-in from Twitter's servers in the USA. For technical reasons, it is necessary for Twitter to process your IP address. In addition, the date and time of your visit to our website are also recorded.
If you are logged in to Twitter while visiting one of our websites equipped with the plug-in, the information collected by the plug-in about your specific visit will be recognized by Twitter. Twitter may assign the information collected in this way to your personal user account there. For example, if you use the Twitter “Share” button, this information will be stored in your Twitter user account and may be published on the Twitter platform. If you want to prevent this, you must either log out of Twitter before visiting our website or make the appropriate settings in your Twitter user account.
Further information about the collection and use of data, as well as your rights and protection options in this regard, is available in Twitter's privacy policy at
.
Google Analytics
We use Google Analytics on our website, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, a subsidiary of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter referred to as “Google”.
Google Analytics helps us analyze the use of the website and measure the effectiveness of our marketing campaigns. The legal basis for this is Art. 6 (1) (a) GDPR. Users can revoke their consent to the use of Google Analytics at any time for the future in accordance with Art. 7 (3) GDPR via the “Cookie settings” on our website.
Information such as the time, place, and frequency of website visits, as well as interactions with the website (e.g., click paths, ads viewed/clicked, clicks on links), including the user's IP address, is transmitted to a Google server in the USA and stored there for a maximum of 2 months.
Google LLC is part of the “Data Privacy Framework,” for which the EU Commission has issued an adequacy decision in accordance with Art. 45 GDPR:
https://www.dataprivacyframework.gov/list
Google also collects “demographic characteristics” and can compile statistics that provide information about the age, gender, and interests of website visitors. This is done through the automated analysis of advertising and information from third-party providers.
If the user has activated personalized ads in their Google account and agrees to Google Analytics, Google can analyze usage behavior across devices—i.e., across all devices that the user has linked to their Google account. Google creates models for cross-device conversions; we only receive anonymous statistics for this purpose, not any personal data.
If the user wishes to deactivate this cross-device analysis, they can disable the “Personalized Advertising” function in their Google account settings at the following link:
https://support.google.com/ads/answer/2662922?hl=de
We use Google Analytics with an anonymization function. This shortens the user's IP address within EU member states or in other signatory states to the EEA Agreement.
Google uses the collected data to evaluate the user's website visit and compile reports on website activity for us. The data is also used to provide other services related to website and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf.
According to its own information, Google will never associate the user's IP address with other data held by Google. Further information and options for preventing data usage are available from Google here:
https://www.google.com/intl/de/policies/privacy/partners
If the user does not agree to the collection of data, they can prevent this by installing the browser add-on to deactivate Google Analytics.
Google Tag Manager
We use Google Tag Manager to integrate various functions on our website. This product is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, a subsidiary of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter referred to as “Google.”
Google Tag Manager is used exclusively to integrate certain content into our website and to enable the management of these functions via an interface provided by Google.
When the website is accessed, the corresponding functions are loaded from a Google server, which may also be located in the USA. The user's IP address is processed in order to provide the functions.
The functions used are listed in full in our privacy policy. The consents not given by the user for certain functions are also observed when using Google Tag Manager.
Google LLC is also part of the “Data Privacy Framework,” for which the EU Commission has issued an adequacy decision in accordance with Art. 45 GDPR:
https://www.dataprivacyframework.gov/list
The legal basis for use is Art. 6 (1) lit. f GDPR. Our legitimate interest lies in the optimization and economic operation of our website.
IONOS WebAnalytics
We use WebAnalytics on our website. This is an analysis service provided by 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, hereinafter referred to as “WebAnalytics,” which allows us to analyze the use of our website.
For the purpose of analysis, data about the type and version of your Internet browser, your operating system, the type of your end device, the website from which you accessed our website (referrer URL), the website(s) of our website that you visit, or the files that you request, date and time of the respective access, and the anonymized IP address of the Internet connection from which our website is being used.
If you have given your consent to this processing, the legal basis is Art. 6 (1) (a) GDPR. The legal basis may also be Art. 6 (1) (f) GDPR. Our legitimate interest lies in the analysis, optimization, improvement, and economic operation of our website.
Google AdWords with conversion tracking
We use the Google AdWords advertising component and conversion tracking on our website. This is a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, hereinafter referred to as “Google”.
We use conversion tracking for the targeted advertising of our offer. If you have given your consent to this processing, the legal basis is Art. 6 para. 1 lit. a GDPR. The legal basis may also be Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the analysis, optimization, and economic operation of our website.
If you click on an ad placed by Google, the conversion tracking we use will store a cookie on your device. These so-called conversion cookies expire after 30 days and are not used to identify you personally.
If the cookie is still valid and you visit a specific page on our website, both we and Google can determine that you clicked on one of our ads placed on Google and that you were then redirected to our website.
Google uses the information collected in this way to compile statistics about visits to our website. This also provides us with information about the number of users who clicked on our ad(s) and the pages of our website that were subsequently visited. However, neither we nor third parties who also use Google AdWords are able to identify you in this way.
You can also prevent or restrict the installation of cookies by adjusting the settings of your Internet browser. At the same time, you can delete cookies that have already been stored at any time. However, the steps and measures required for this depend on the Internet browser you are using. If you have any questions, please use the help function or documentation of your Internet browser or contact its manufacturer or support.
Google also offers further information on this topic, in particular on the options for preventing data use, at
https://services.google.com/sitestats/de.html
https://www.google.com/policies/technologies/ads/
http://www.google.de/policies/privacy/
.
Google Remarketing or Google's “Similar Audiences” component
We use the remarketing or “Similar Audiences” function on our website. This is a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, hereinafter referred to as “Google.”
We use this function to place interest-based, personalized advertising on third-party websites that also participate in Google's advertising network.
If you have given your consent to this processing, the legal basis is Art. 6 (1) (a) GDPR. The legal basis may also be Art. 6 (1) (f) GDPR. Our legitimate interest lies in the analysis, optimization, and economic operation of our website.
In order to enable this advertising service, Google stores a cookie with a string of numbers on your device via your Internet browser during your visit to our website. This cookie records both your visit and your use of our website in anonymized form. However, no personal data is passed on. If you then visit the website of a third party who also uses Google's advertising network, you may see advertisements that are related to our website or our offers there.
To permanently disable this function, Google offers a browser plugin for the most common Internet browsers at
https://www.google.com/settings/ads/plugin
.
You can also opt out of the use of cookies from certain providers, for example via
http://www.youronlinechoices.com/uk/your-ad-choices
or
http://www.networkadvertising.org/choices/
.
Through so-called cross-device marketing, Google may also track your usage behavior across multiple devices, so that you may be shown interest-based, personalized advertising even when you switch devices. However, this requires that you have agreed to link your browsing history to your existing Google account.
Google provides further information on Google remarketing at
https://www.google.com/privacy/ads/
.
WhatsApp contact
The provider enables customers to contact them via the WhatsApp messenger service, among other things. WhatsApp is a service provided by WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, hereinafter referred to as WhatsApp, a subsidiary of Facebook.
When the user communicates with the provider via WhatsApp, both the provider and WhatsApp receive the user's mobile phone number and the information that the user has contacted the provider.
The aforementioned data is also forwarded by WhatsApp to Facebook servers in the USA and processed by WhatsApp and Facebook in accordance with the WhatsApp privacy policy, which also includes processing for their own purposes, such as improving the WhatsApp service.
_____________________
However, in the opinion of the data protection supervisory authorities, the USA does not currently have an adequate level of data protection. However, there are so-called standard contractual clauses:
https://faq.whatsapp.com/general/about-standard-contractual-clauses
However, these are private law agreements and therefore have no direct effect on the access options of the authorities in the USA.
_____________________
Further details on the purpose and scope of data collection and the further processing of this data by WhatsApp and Facebook, as well as related rights and settings options for protecting privacy, can be found in WhatsApp's privacy policy:
https://www.whatsapp.com/legal/#privacy-policy.
The legal basis for this processing and the transfer to WhatsApp is Art. 6 (1) (b) GDPR, insofar as the contact concerns an existing contractual relationship or serves to initiate such a contractual relationship. If the contact is not made for the above purposes, the legal basis is Art. 6 (1) lit. f GDPR. The provider's legitimate interest lies in improving the quality of service.
Muster-Datenschutzerklärung der Anwaltskanzlei Weiß & Partner
