Privacy policy

1. Data protection at a glance

General information

The following information provides an overview of what happens to your personal data when you visit our website, contact us, subscribe to our newsletter or place an order or submit an enquiry via our Shopify shop. Personal data means any data by which you can be personally identified, for example your name, address, email address, telephone number, order data or technical usage data.

Who is responsible for data processing?

The controller responsible for data processing on this website is:

Kredenbacher Hof GmbH & Co. Sonnenblumen KG
Michelriether Str. 18
97839 Esselbach
Germany
Telephone: +49 9394 99400-20
Email: info@kredenbacherhof.de

How do we collect your data?

Some data is collected when you provide it to us, for example via contact forms, newsletter registration, customer account, order or checkout process, or by email. Other data is collected automatically when you visit the website by our IT systems or by service providers used by us, for example browser type, operating system, time of page access, IP address, referrer URL, cart and checkout events, and cookie and consent information.

What do we use your data for?

We use personal data in particular to provide the website, process enquiries, process orders and payments, comply with legal obligations, prevent fraud and misuse, ensure technical security, communicate with customers and business partners and, only where there is a legal basis for doing so, for newsletters, reach measurement, marketing and conversion tracking.

What rights do you have?

Subject to the statutory requirements, you have in particular the rights of access, rectification, erasure, restriction of processing, data portability and objection. You may withdraw any consent you have given at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority.

2. General information and mandatory notices

Data protection

We treat your personal data confidentially and in accordance with the applicable data protection laws, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG), as well as this Privacy Policy.

Please note that data transmission on the internet, for example when communicating by email, may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.

Legal bases for processing

We process personal data on the following legal bases:

·  Art. 6(1)(a) GDPR, where you have consented to processing, for example newsletters, analytics or marketing cookies;

·  Art. 6(1)(b) GDPR, insofar as the processing is necessary for the performance of a contract or for taking steps prior to entering into a contract, for example enquiries, offers, orders, customer account, delivery and payment;

·  Art. 6(1)(c) GDPR, insofar as we are legally obliged to process data, for example under commercial and tax retention obligations;

·  Art. 6(1)(f) GDPR, insofar as we or third parties have a legitimate interest in the processing, for example technical provision, IT security, fraud prevention, direct marketing to existing customers to the extent permitted by law, and the establishment, exercise or defence of legal claims.

Section 25 TDDDG also applies to the storage of information on your terminal device or access to information that is already stored on your terminal device. Technically necessary storage or access takes place on the basis of Section 25(2) TDDDG. We use non-essential cookies, pixels and similar technologies only on the basis of your consent pursuant to Section 25(1) TDDDG.

Storage period

We store personal data only for as long as is necessary for the respective purposes or for as long as statutory retention obligations apply. Business correspondence and tax or commercial documents may, in particular, be retained for six or ten years in accordance with commercial and tax law requirements. Where you have given consent, we store the data processed on that basis until consent is withdrawn or for as long as is necessary to document the consent.

Recipients of data

We disclose personal data only where this is necessary for contract performance, compliance with legal obligations, on the basis of consent or on the basis of legitimate interests. Recipients may include, in particular: hosting and shop system providers, technical service providers, payment service providers, shipping and logistics service providers, tax advisers, legal advisers, authorities, banks, newsletter and communication service providers, and analytics and marketing service providers.

Transfers to third countries

Some of the service providers we use may also process data outside the European Union or the European Economic Area. Where personal data is transferred to third countries, this is carried out only on the basis of the statutory requirements, in particular adequacy decisions of the European Commission, EU Commission standard contractual clauses, binding corporate rules or explicit consent, where required.

SSL or TLS encryption

For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection, among other things, by the fact that the browser address line begins with "https://".

Your rights

Within the framework of the applicable statutory provisions, you have the right at any time to obtain information free of charge about your stored personal data, its origin and recipients and the purpose of the data processing. You may also have the right to rectification, erasure, restriction of processing, data portability and objection to certain processing operations.

Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.

Right to lodge a complaint with a supervisory authority

If you believe that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with a data protection supervisory authority. For companies based in Bavaria, the competent authority is generally:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
www.lda.bayern.de

3. Data processing when visiting our website

Server log files and technical provision

When you access our website, information that your browser transmits to our servers or to the servers of our technical service providers is processed automatically. This may include: IP address, date and time of access, browser type and browser version, operating system, referrer URL, pages accessed, amount of data transferred, language settings, device information and status codes.

Processing is carried out for the technical provision of the website, stability and security, error analysis and misuse prevention. The legal basis is Art. 6(1)(f) GDPR. Where data is required for the conclusion or performance of a contract, Art. 6(1)(b) GDPR also applies.

Shopify as shop system, hosting and technical infrastructure

We operate our online shop with Shopify. Depending on the contractual arrangement, the provider is Shopify International Limited, 2nd Floor, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland, or other companies of the Shopify group.

Shopify provides us with the technical shop infrastructure. This includes, in particular, hosting, content delivery network, shopping cart, checkout, customer account, order management, shop analytics, security functions, fraud prevention, localisation, search functions and interfaces to payment and shipping service providers. In this context, Shopify processes personal data of website visitors, customers and contact persons to the extent necessary for the operation, security, analytics, order processing and support of the shop.

The data processed may include, in particular: technical access data, cookie and consent information, cart contents, order data, delivery and billing data, email address, telephone number, payment and transaction data, customer account data, device and browser information and event data such as page views, product views, searches, add-to-cart events and checkout steps.

The legal bases are Art. 6(1)(b) GDPR for shop, cart, checkout and order functions, Art. 6(1)(c) GDPR for legal obligations, Art. 6(1)(f) GDPR for security, stability, fraud prevention and technical optimisation, and Art. 6(1)(a) GDPR for analytics and marketing functions that require consent.

Shopify may also transfer data to companies of the Shopify group and to subprocessors. According to Shopify, personal data of customers from the EEA, the UK and Switzerland is initially processed by Shopify International Limited in Ireland; Shopify group companies and subprocessors may be involved in the provision of the services.

Shopify Network Intelligence and enhanced Shopify services

We use Shopify as our shop system and, as part of the Shopify services, also use functions that may be provided under "Shopify Network Intelligence" or enhanced Shopify services. In this context, Shopify may process personal data of our customers and website visitors together with data from other Shopify shops in order to provide, secure, improve and personalise Shopify services.

These services may serve, in particular, to improve and personalise the shopping experience, improve shop performance, prevent fraud and misuse, analyse shop interactions, optimise payment and checkout functions and provide marketing and communication functions.

The data processed in this context may include, in particular, technical information such as IP address, device and browser information, cookies and similar identifiers, information about page views, searches, product views, cart and checkout interactions, and order and customer data, insofar as such data is generated when using our shop.

Shopify may process this data for the provision and improvement of Shopify services and for so-called enhanced services. According to Shopify, other merchants do not have access to our customer data.

Where consent is required for this processing, the processing takes place only on the basis of your consent. You may withdraw your consent at any time via the cookie/privacy settings of our shop. In addition, you can obtain information about processing by Shopify through Shopify's privacy portal and exercise certain data protection rights against Shopify there.

Further information on the processing of personal data by Shopify can be found in Shopify's Privacy Policy and in the Shopify Privacy Portal.

Customer account and login

If you create a customer account or use the login function, we process the data required for this purpose, for example your name, email address, address, order history and login information. The purpose is to provide the customer account, manage orders, simplify the processing of future purchases and communicate with you. The legal basis is Art. 6(1)(b) GDPR.

Shopping cart, checkout and order processing

If you place products in the shopping cart or initiate an order, we process the data required for this purpose. This includes in particular contact details, billing and delivery address, ordered products, prices, payment method, delivery status, order number, transaction data and communication data. Processing is carried out for taking steps prior to entering into a contract, contract performance, payment processing, delivery, invoicing, customer communication and compliance with legal obligations. The legal bases are Art. 6(1)(b) and (c) GDPR.

As our offering is primarily aimed at business customers, wholesale, processors, commercial kitchens, communal catering, riding stables and similar purchasers, we often process personal data of contact persons within companies or institutions. These data are also processed exclusively for the purposes stated above.

Contact form and enquiries by email or telephone

If you contact us via a contact form, by email, telephone or in any other way, we process the information you provide in order to handle the enquiry. This may include: name, company, email address, telephone number, message, information on quantity requirements, field of use and other information provided by you.

The legal basis is Art. 6(1)(b) GDPR insofar as your enquiry is related to a contract or pre-contractual measures. In all other cases, the legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the efficient handling of your enquiry. Where you have given consent, the legal basis is Art. 6(1)(a) GDPR.

hCaptcha in forms

Shopify may protect forms, in particular contact, customer account and newsletter forms, with hCaptcha. The provider is Intuition Machines, Inc., USA. hCaptcha is used to check whether entries on our website are made by a human or by automated programs. In this context, in particular the IP address, device and browser information, mouse movements, dwell time and interaction data may be processed.

The service is used to protect against spam, misuse and automated attacks. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the security and functionality of our forms and our shop. To the extent that hCaptcha stores or accesses information on your terminal device, this is done, where technically necessary, on the basis of Section 25(2) TDDDG.

4. Cookies, consent management and tracking technologies

Cookies and similar technologies

Our website uses cookies, local storage technologies, pixels, tags and similar technologies. Some of these are technically necessary for the website, shopping cart, checkout, language settings, security functions and customer account to work. Others serve, only with your consent, analytics, reach measurement, advertising, conversion measurement and personalisation.

We use technically necessary cookies and storage access on the basis of Section 25(2) TDDDG and Art. 6(1)(f) GDPR or Art. 6(1)(b) GDPR. We use non-essential cookies and similar technologies only with your consent pursuant to Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

Consentmo GDPR Compliance / cookie banner

We use the consent management tool "Consentmo GDPR Compliance" in the shop. The tool manages your consents for cookie and tracking categories, for example "necessary", "analytics", "marketing" and "functionality". In this context, consent status, selected categories, timestamps, device and browser information and technical IDs may be processed and stored in order to document your selection and take it into account when you visit again.

The legal basis for storing your consent is Art. 6(1)(c) GDPR, insofar as we are legally obliged to provide evidence, and Art. 6(1)(f) GDPR. Our legitimate interest lies in legally compliant consent management. Where storage is technically necessary, it is carried out on the basis of Section 25(2) TDDDG.

You may change or withdraw your selection at any time via the cookie banner. Withdrawal applies with effect for the future.

Google Consent Mode

We use Google Consent Mode to transmit the status of your consent to Google services. This allows Google tags to adapt their behaviour to your selection in the cookie banner. Depending on the configuration and consent status, Google services may either be blocked or receive only limited, cookieless signals. Where consent has been granted, the respective Google services may set cookies and process measurement data.

The legal basis for integrating and transmitting consent-related signals is Art. 6(1)(f) GDPR, insofar as this is necessary for the technical control and documentation of your consent. The actual analytics or marketing processing takes place only on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG, unless there is a technical necessity.

5. Analytics, marketing and web pixels

Shopify Analytics, Shopify Web Pixels, Trekkie and Monorail

As part of the shop, Shopify uses its own analytics, event and performance technologies, including Shopify Analytics, Web Pixels, Trekkie, Shop Events Listener and Monorail. These technologies may process events such as page views, product views, searches, cart events, checkout steps, purchases, technical performance data and error events.

Technically necessary processing is carried out for the provision, security, stability, error analysis and performance optimisation of the shop on the basis of Art. 6(1)(f) GDPR. Where Shopify pixels or third-party pixels are used for analytics, marketing or remarketing, this is done only in accordance with your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

Google Analytics 4 and Google Tag

Where you have given consent, we use Google Analytics 4 and Google Tag for reach measurement and analysis of the use of our shop. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics 4 may process events such as page views, searches, product views, cart events, checkout steps, purchases, device information, browser information, approximate location data, IP address, referrer URL and interaction data. According to Google, Google Analytics 4 does not use IP addresses for logging or storage in the previous manner; nevertheless, the IP address may technically be processed for data transmission.

The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time via the cookie banner.

Google Ads / conversion tracking / Google marketing tags

Where you have given consent, we may use Google Ads, Google Tag and conversion tracking to measure the success of advertising measures and evaluate advertisements.

In conversion tracking, information about page views, product views, cart and checkout events, purchases, transaction values, device and browser data and cookie IDs or similar identifiers may be processed. Processing takes place only on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time via the cookie banner.

Meta Pixel (Facebook Pixel) and social media links

We maintain social media profiles on Facebook and Instagram and link to these profiles from our website. When you merely visit our website, no data is generally transmitted to Meta through simple text or image links. If you click on a link to Facebook or Instagram, you leave our website; Meta Platforms Ireland Limited, Ireland, is responsible for the subsequent data processing.

On individual pages of our shop, and only where you have given consent for this, we use the Meta Pixel, formerly Facebook Pixel. The provider is Meta Platforms Ireland Limited, Ireland. The reviewed Hofladen page contains a Meta Pixel integration with Pixel ID 766115934644946. In the integration visible there, the script is loaded from connect.facebook.net, the pixel is initialised and the PageView event is triggered as soon as marketing consent is present via the Shopify Customer Privacy function.

With the help of the Meta Pixel, we can determine whether users access our website after clicking on a Facebook or Instagram advertisement and which pages they visit. This allows us to measure the effectiveness of our advertising measures, create or exclude target groups for advertisements, create so-called Custom Audiences or similar audiences and display our advertisements on Meta platforms in a more interest-based manner.

In this context, the following data in particular may be processed and transmitted to Meta: pages and URLs accessed, referrer URL, time of page access, technical browser and device information, IP address, cookies and other online identifiers, Pixel ID, event name, consent status and, where applicable, further interaction data if additional Meta events are configured. Based on the pages reviewed to date, the PageView event was expressly visible on the Hofladen page.

The legal basis for setting or reading non-essential cookies and similar technologies is your consent pursuant to Section 25(1) TDDDG. The legal basis for the subsequent processing of personal data is Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future via the cookie/privacy settings of our shop.

Meta processes the information transmitted via Meta Business Tools in accordance with Meta's terms and privacy notices. Processing by Meta companies outside the EU/EEA, in particular in the USA, cannot be ruled out. Further information can be found in Meta's Privacy Policy, Meta's Cookie Policy and the Terms for Meta Business Tools.

ProvenExpert

A notice or link to our ProvenExpert profile may be displayed on our website. Insofar as this is merely an image or text link, no data is transmitted to ProvenExpert when you merely visit our website. If you click on the link, you leave our website; ProvenExpert or the operator of the ProvenExpert platform is responsible for the subsequent data processing.

6. Newsletter and electronic communications

Newsletter registration

On our website, you can register to receive news, offers and information from Kredenbacher Hof. The newsletter is aimed in particular at business customers and interested parties. For registration, we process your email address and any other voluntary information. In addition, where technically provided, we store the date, time, IP address and consent status in order to be able to document the registration.

Dispatch takes place only with your consent pursuant to Art. 6(1)(a) GDPR. Logging of the registration is carried out on the basis of Art. 6(1)(f) GDPR; our legitimate interest lies in documenting proper consent.

You can unsubscribe from the newsletter at any time, for example via an unsubscribe link in the newsletter or by sending us a message. The lawfulness of processing carried out up to the time of unsubscription remains unaffected.

Shopify Email and marketing automations

We may use Shopify Email or Shopify marketing functions to send newsletters and electronic marketing communications. Automated messages may also be triggered through these functions, for example reminders in connection with an abandoned checkout or shopping cart, provided that the applicable legal requirements are met.

In this context, in particular email address, name, order and cart information, checkout status, consent and unsubscribe status, times of registration, dispatch and interaction, and technical delivery data may be processed. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR or, where legally permitted, Art. 6(1)(f) GDPR for direct marketing to existing customers. You may object to receiving such communications at any time or withdraw any consent you have given.

Direct marketing to existing customers

Where we have obtained your email address in connection with the sale of goods or services and the statutory requirements are met, we may send you information about similar goods or services of our own. You may object to this use at any time without incurring any costs other than transmission costs according to the basic rates. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in addressing existing customers for advertising purposes to the extent permitted by law.

7. Payment processing

General information on payment data

If you place a paid order in the shop, payment data is processed. Depending on the payment method selected, this may include name, billing address, delivery address, email address, telephone number, order number, cart contents, invoice amount, currency, payment status, transaction data, fraud prevention data and, in the case of card or wallet payments, shortened or tokenised payment information. Full credit card data is generally not stored by us, but is processed by the respective payment service providers.

The legal basis is Art. 6(1)(b) GDPR for payment processing and contract performance, Art. 6(1)(c) GDPR for legal obligations and Art. 6(1)(f) GDPR for fraud prevention, receivables management and IT security.

Shopify Payments, credit cards, debit cards, EPS, Bancontact and local payment methods

We may use Shopify Payments as a payment service. Shopify Payments enables the processing of various payment methods, in particular credit and debit cards and, depending on country, availability and checkout configuration, local payment methods such as EPS or Bancontact. The provider is Shopify or the respective payment processor named in the Shopify Payments terms.

Shopify and participating payment processors process payment data for authorisation, execution, settlement, reversal, fraud prevention, risk analysis, compliance with legal obligations, anti-money-laundering and sanctions checks and the provision of payment services. Payment service providers may in some cases act as independent controllers.

PayPal

If you pay with PayPal, the data required for payment processing is transmitted to PayPal. The provider for customers in Germany is generally PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg. PayPal processes data for payment processing, fraud prevention, risk analysis, identity verification, compliance with legal obligations and, where applicable, the provision of further PayPal services. PayPal's privacy notices apply additionally to processing by PayPal.

Klarna

If you choose a Klarna payment method, the data required for payment processing is transmitted to Klarna. The provider is Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. Klarna may process, in particular, contact, order, payment and, where applicable, creditworthiness data in order to provide the selected payment method, carry out identity and credit checks, prevent fraud and comply with legal obligations. Klarna's privacy notices apply additionally to processing by Klarna.

Apple Pay

If you use Apple Pay, payment processing is carried out via Apple and the participating payment service providers or card issuers. Apple may process technical information, device information and payment information required for secure authorisation and execution of the payment. The actual payment is generally processed using tokenised or encrypted payment data. Apple's privacy notices apply additionally to processing by Apple.

Google Pay

If you use Google Pay, payment processing is carried out via Google and the participating payment service providers or card issuers. Google may process payment profile, device, transaction and account information to the extent necessary to provide and process Google Pay. The Google Payments privacy notices and the Google Privacy Policy apply additionally to processing by Google.

Shop Pay

If you use Shop Pay, payment and checkout processing is carried out via Shopify or Shop. Shop Pay may process your email address, telephone number, delivery and billing address, payment information, order data, device information and verification information in order to provide an accelerated checkout, stored payment and delivery information, security checks and payment processing. Shopify/Shop's privacy notices apply additionally to processing by Shopify/Shop.

8. Shipping, delivery and business partners

For the delivery of ordered goods, we transmit the data required for this purpose to DPD, our shipping and logistics service provider, for example name, delivery address, email address, telephone number, order data and, where applicable, delivery instructions. The legal basis is Art. 6(1)(b) GDPR. Where we have shipping information or delivery notifications transmitted to you, this is likewise done for contract performance or on the basis of legitimate interests in transparent delivery.

9. External links, social media and map services

External links

Our website contains links to external websites, in particular Facebook, Instagram, YouTube, ProvenExpert and Google Maps/route planning. If you click on an external link, you leave our website. From that point onwards, the respective external provider is responsible for further data processing.

Google Maps / route planning

A link to route planning via Google Maps may be displayed on our contact page. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. If you click on the link, you will be redirected to Google; Google then processes data on its own responsibility. Further details on Google Maps, static map images and Google services can be found in Section 10 of this Privacy Policy.

Social media profiles

We maintain online presences on social networks and platforms. When you visit our profiles, the privacy policies and terms of use of the respective providers apply. We process data that you provide to us via these platforms, for example messages, comments or interactions, for communication with you and for external presentation. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in communicating with interested parties, customers and business partners.

10. Web fonts, media files and Google services on individual pages

Our website uses fonts and media files that are predominantly provided via Shopify or the Shopify CDN. When you access the website, your browser may establish connections to Shopify servers for this purpose. Processing is carried out for the uniform, secure and performant display of the website on the basis of Art. 6(1)(f) GDPR.

Static map images and Google Maps route planning

According to the integration currently reviewed, a static map image is displayed on our contact page as a media file provided via the website or Shopify. In addition, the contact page contains a link to route planning via Google Maps. The provider of the Google services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

When merely displaying a static map image provided locally or via Shopify, no Google Maps content is loaded directly according to the integration currently reviewed. However, if you click on the "Route planen" link or a comparable Google Maps link, you leave our website and are redirected to Google Maps. Google then processes data on its own responsibility, in particular your IP address, device and browser information, referrer information, the time of access, the requested route or destination and, if you allow this in your browser or device, location data.

The provision of a route planning function is based on our legitimate interest in a user-friendly display of directions and easy findability of our location pursuant to Art. 6(1)(f) GDPR. If an embedded Google Maps map or other Google content is loaded directly on our website in the future, this will take place only on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as non-technically necessary cookies, device identifiers or similar technologies are used.

Google Consent Mode and Google tags

Google Consent Mode V2 is integrated on our website via our consent management tool. This allows the status of your consent to be transmitted to Google services so that Google tags can adapt their behaviour to your selection in the cookie banner. Depending on the consent status, Google services may be blocked or receive only limited signals; where consent has been granted, the respective Google services may set cookies and process measurement or marketing data.

In the reviewed shop files, Google tag or Google marketing identifiers such as G-HRSECRF6CJ, GT-573JPK3X and MC-BR6DW421V6 are visible. Through these tags, where you have given consent, in particular page views, searches, product views, cart and checkout events, purchases, device and browser information, referrer information, approximate location information, IP address and cookies or comparable online identifiers may be processed.

The legal basis for analytics and marketing processing via Google services is your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time with effect for the future via the cookie/privacy settings of our shop.

No direct Google Fonts integration based on the current review

Based on the shop file currently reviewed, the visible fonts are loaded via Shopify or the Shopify CDN. A direct integration of Google Fonts from Google servers was not materially visible in the reviewed files. If Google Fonts are directly integrated from Google servers in the future, this processing will be described separately and, where required, controlled via the consent management tool.

11. Automated decision-making

As a general rule, we do not carry out automated decision-making within the meaning of Art. 22 GDPR. However, payment service providers, in particular Klarna, PayPal, Shopify Payments or participating payment processors, may use automated procedures in the context of fraud prevention, risk analysis, payment authorisation, identity verification or credit checks. Details can be found in the privacy notices of the respective payment service providers.

12. Amendments to this Privacy Policy

We reserve the right to amend this Privacy Policy if the legal situation, our website, service providers used by us or data processing operations change. The version published on this website at any given time applies.