Skip to content
Free shipping with DHL 🇩🇪 🇦🇹 | 🇪🇺 from €20
+250,000 customers
Excellent

Data Protection

  • 1) Information about the collection of personal data and contact details of the controller

    1.1 We are pleased that you visit our website and thank you for your interest. Below we inform you about the handling of your personal data when using our website. Personal data are all data with which you can be personally identified.

    1.2 The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is MDM Healthcare Deutschland GmbH, Angersbachstraße 20, 34127 Kassel, Germany, Tel.: +49(0)561-8201696, Fax: +49(0)561-8202905, E-Mail: info@mdmhealthcare.eu. The person responsible for the processing of personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of the processing of personal data.

    1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser bar.

    2) Data collection when visiting our website

    When using our website for purely informational purposes, i.e., if you do not register or otherwise provide us with information, we only collect such data that your browser transmits to our server (so-called "server log files"). When you access our website, we collect the following data that is technically necessary for us to display the website to you:

    Our visited website
  • Date and time at the time of access
  • Amount of data sent in bytes
  • Source/referrer from which you accessed the site
  • Browser used
  • Operating system used
  • Used IP address (if applicable: in anonymized form)

The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. There is no transfer or other use of the data. However, we reserve the right to retrospectively check the server log files if there are concrete indications of unlawful use.

3) Cookies

To make visiting our website attractive and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e., after closing your browser (so-called session cookies). Other cookies remain on your device and allow us or our partner companies (third-party cookies) to recognize your browser again on your next visit (persistent cookies). When cookies are set, they collect and process certain user information such as browser and location data as well as IP address values to varying extents. Persistent cookies are automatically deleted after a predetermined period, which can vary depending on the cookie.

In part, the cookies serve to simplify the ordering process by storing settings (e.g., remembering the contents of a virtual shopping cart for a later visit to the website). If personal data is also processed by individual cookies implemented by us, the processing takes place in accordance with Art. 6 para. 1 lit. b GDPR either for the execution of the contract or in accordance with Art. 6 para. 1 lit. f GDPR to protect our legitimate interests in the best possible functionality of the website as well as a customer-friendly and effective design of the site visit.

We may work with advertising partners who help us make our internet offer more interesting for you. For this purpose, cookies from partner companies are also stored on your hard drive during your visit to our website (third-party cookies). If we cooperate with the aforementioned advertising partners, you will be individually and separately informed about the use of such cookies and the scope of the information collected in the following paragraphs.

Please note that you can set your browser to inform you about the setting of cookies and decide individually whether to accept them or exclude the acceptance of cookies for certain cases or in general. Each browser differs in how it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find this for the respective browsers at the following links:

Internet Explorer: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
Chrome: https://support.google.com/chrome/answer/95647?hl=de&hlrm=en
Safari: https://support.apple.com/de-de/guide/safari/sfri11471/mac
Opera: https://help.opera.com/en/latest/web-preferences/#cookies

Please note that if you do not accept cookies, the functionality of our website may be limited.

4) Contact

In the context of contacting us (e.g., via contact form or email), personal data is collected. Which data is collected in the case of a contact form can be seen from the respective contact form. This data is stored and used exclusively for the purpose of responding to your request or for contacting you and the associated technical administration. The legal basis for processing the data is our legitimate interest in responding to your request according to Art. 6 para. 1 lit. f GDPR. If your contact aims at concluding a contract, the additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted after your inquiry has been finally processed; this is the case when the circumstances indicate that the matter has been conclusively clarified and provided that no legal retention obligations oppose this.

5) Data processing when opening a customer account and for contract processing

According to Art. 6 para. 1 lit. b GDPR, personal data will continue to be collected and processed if you provide it to us for the execution of a contract or when opening a customer account. Which data is collected can be seen from the respective input forms. Deletion of your customer account is possible at any time and can be done by sending a message to the above-mentioned address of the controller. We store and use the data you provide for contract processing. After complete processing of the contract or deletion of your customer account, your data will be blocked with regard to tax and commercial retention periods and deleted after these periods expire, unless you have explicitly consented to further use of your data or a legally permitted further use of data by us has been reserved, about which we will inform you accordingly below.

6) Use of your data for direct advertising

6.1 Sign up for our email newsletter

If you sign up for our email newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your email address. Providing additional data is voluntary and is used to address you personally. For sending the newsletter, we use the so-called double opt-in procedure. This means that we will only send you an email newsletter after you have explicitly confirmed that you consent to receiving the newsletter. We will then send you a confirmation email asking you to confirm by clicking a corresponding link that you want to receive newsletters in the future.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 para. 1 lit. a GDPR. When registering for the newsletter, we store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any possible misuse of your email address at a later time. The data we collect when registering for the newsletter is used exclusively for the purpose of advertising communication via the newsletter. You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending a corresponding message to the responsible party named above. After unsubscribing, your email address will be deleted from our newsletter distribution list immediately, unless you have explicitly consented to further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this statement.

6.2 Newsletter sending via MailChimp
The sending of our email newsletters is carried out by the technical service provider The Rocket Science Group, LLC d/b/a MailChimp, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA (http://www.mailchimp.com/), to whom we pass on the data you provided when registering for the newsletter. This transfer is made in accordance with Art. 6 para. 1 lit. f GDPR and serves our legitimate interest in using an effective, secure, and user-friendly newsletter system. Please note that your data is usually transferred to a MailChimp server in the USA and stored there.
MailChimp uses this information to send and statistically evaluate the newsletters on our behalf. For the evaluation, the sent emails include so-called web beacons or tracking pixels, which are one-pixel image files stored on our website. This allows us to determine whether a newsletter message was opened and which links, if any, were clicked. With the help of the web beacons, Mailchimp automatically creates general, non-personal statistics about the response behavior to newsletter campaigns. Based on our legitimate interest in the statistical evaluation of newsletter campaigns to optimize advertising communication and better align with recipient interests, data of the respective newsletter recipient are also collected and processed through the web beacons in accordance with Art. 6 para. 1 lit. f GDPR (email address, time of access, IP address, browser type, and operating system). This data allows an individual conclusion about the newsletter recipient and is processed by Mailchimp to automatically create statistics that show whether a specific recipient has opened a newsletter message.
If you want to deactivate data analysis for statistical evaluation purposes, you must unsubscribe from the newsletter.
MailChimp may also use this data itself in accordance with Art. 6 para. 1 lit. f GDPR due to its own legitimate interest in the needs-based design and optimization of the service as well as for market research purposes, for example to determine from which countries the recipients come. However, MailChimp does not use the data of our newsletter recipients to contact them itself or to pass it on to third parties.
To protect your data in the USA, we have concluded a data processing agreement ("Data-Processing-Agreement") with MailChimp based on the standard contractual clauses of the European Commission to enable the transfer of your personal data to MailChimp. This data processing agreement can be viewed at the following internet address if interested: https://mailchimp.com/legal/forms/data-processing-agreement
MailChimp is also certified under the US-European data protection agreement "Privacy Shield" and thus commits to complying with EU data protection requirements.
You can view MailChimp's privacy policy here: https://mailchimp.com/legal/privacy/

7) Data processing for order processing

7.1 The personal data we collect is passed on to the transport company commissioned with the delivery as part of the contract processing, insofar as this is necessary for the delivery of the goods. We pass on your payment data to the commissioned credit institution as part of the payment processing, provided this is necessary for the payment processing. If payment service providers are used, we explicitly inform you about this below. The legal basis for the transfer of data is Art. 6 para. 1 lit. b GDPR.

7.2 Transfer of personal data to shipping service providers

- DHL
If the delivery of the goods is carried out by the transport service provider DHL (Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn), we forward your email address in accordance with Art. 6 para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification to DHL, provided you have given your explicit consent for this during the ordering process. Otherwise, for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR, we only forward the recipient's name and delivery address to DHL. The transfer is only made to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with DHL or delivery notification is not possible.
Consent can be revoked at any time with effect for the future towards the responsible party named above or towards the transport service provider DHL.

7.3 Use of payment service providers (payment services)

- Amazon Pay
When selecting the payment method "Amazon Pay," the payment processing is carried out by the payment service provider Amazon Payments Europe s.c.a., 5 Rue Plaetis, L-2338 Luxembourg (hereinafter: "Amazon Payments"), to whom we forward the information you provided during the ordering process along with the information about your order in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data is made exclusively for the purpose of payment processing with the payment service provider Amazon Payments and only to the extent necessary for this purpose. Further information about the privacy policy of Amazon Payments can be found at the following internet address: https://pay.amazon.com/de/help/201751600
- Paymill
When selecting the payment methods "Credit card payment via Paymill" or "Direct debit payment via Paymill," the payment processing is carried out by the technical service provider Paymill GmbH, St.-Cajetan-Straße 43, 81669 Munich, to whom we forward your billing data (name, address, credit card number, invoice amount, currency, and transaction number) for the purpose of payment processing in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data is made exclusively for the purpose of payment processing and only to the extent necessary for this purpose.
To process the payment, Paymill GmbH forwards your billing data based on Art. 6 para. 1 lit. b GDPR to the acquirers Lufthansa AirPlus Servicekarten GmbH, Dornhofstr. 10, 63263 Neu-Isenburg or Wirecard Bank AG, Einsteinring 35, 85609 Aschheim. This transfer is made exclusively for the purpose of processing the payment and only to the extent necessary for this purpose. Further information on how Paymill handles personal data can be found in Paymill's privacy policy at https://www.paymill.com/de/datenschutz
- Paypal
When paying via PayPal, credit card via PayPal, direct debit via PayPal, or – if offered – "purchase on account" or "installment payment" via PayPal, we pass on your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") as part of the payment processing. The transfer takes place in accordance with Art. 6 para. 1 lit. b GDPR and only to the extent necessary for payment processing.
PayPal reserves the right to conduct a credit check for the payment methods credit card via PayPal, direct debit via PayPal, or – if offered – "purchase on account" or "installment payment" via PayPal. For this purpose, your payment data may be passed on to credit agencies in accordance with Art. 6 para. 1 lit. f GDPR based on PayPal's legitimate interest in determining your creditworthiness. PayPal uses the result of the credit check regarding the statistical probability of default for the purpose of deciding on the provision of the respective payment method. The credit report may contain probability values (so-called score values). As far as score values are included in the credit report result, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things but not exclusively, address data. For further data protection information, including the credit agencies used, please refer to PayPal's privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contract-compliant payment processing.
- SOFORT
When selecting the payment method "SOFORT," the payment processing is carried out by the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter "SOFORT"), to whom we pass on the information you provided during the ordering process along with the information about your order in accordance with Art. 6 para. 1 lit. b GDPR. Sofort GmbH is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden). The transfer of your data takes place exclusively for the purpose of payment processing with the payment service provider SOFORT and only to the extent necessary for this purpose. At the following internet address, you can find more information about SOFORT's data protection provisions: https://www.klarna.com/sofort/datenschutz

8) Use of Social Media: Videos

Use of YouTube Videos

This website uses the YouTube embedding function to display and play videos from the provider "YouTube," which belongs to Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").

The extended privacy mode is used here, which according to the provider's information only activates the storage of user information when the video(s) are played. When the playback of embedded YouTube videos is started, the provider "YouTube" uses cookies to collect information about user behavior. According to "YouTube," these serve, among other things, to collect video statistics, improve user-friendliness, and prevent abusive behavior. If you are logged into Google, your data will be directly assigned to your account when you click on a video. If you do not want the assignment with your profile on YouTube, you must log out before activating the button. Google stores your data (even for users not logged in) as usage profiles and evaluates them. Such evaluation is carried out in particular according to Art. 6 para. 1 lit. f GDPR based on Google's legitimate interests in displaying personalized advertising, market research, and/or needs-based design of its website. You have the right to object to the creation of these user profiles, whereby you must contact YouTube to exercise this right. In the context of using YouTube, personal data may also be transmitted to the servers of Google LLC in the USA.
Regardless of the playback of the embedded videos, a connection to the Google network is established every time this website is accessed, which can trigger further data processing operations without our influence.

In the event of the transfer of personal data to Google LLC, based in the USA, Google LLC has certified itself under the US-European data protection agreement "Privacy Shield," which ensures compliance with the data protection level applicable in the EU. A current certificate can be viewed here: https://www.privacyshield.gov/list

Further information on data protection at "YouTube" can be found in the provider's privacy policy at: https://www.google.de/intl/de/policies/privacy

9) Online Marketing

Use of Google Ads Conversion Tracking

This website uses the online advertising program "Google Ads" and within the framework of Google Ads the conversion tracking of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). We use the offer from Google Ads to draw attention to our attractive offers on external websites with the help of advertising media (so-called Google Adwords). We can determine the success of the individual advertising measures in relation to the data of the advertising campaigns. Our goal is to show you advertising that is of interest to you, to make our website more interesting for you, and to achieve a fair calculation of advertising costs.

The cookie for conversion tracking is set when a user clicks on an ad placed by Google Ads. Cookies are small text files that are stored on your computer system. These cookies usually expire after 30 days and are not used for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google Ads customer receives a different cookie. Cookies cannot be tracked across the websites of Google Ads customers. The information collected using the conversion cookie is used to create conversion statistics for Google Ads customers who have opted for conversion tracking. The customers learn the total number of users who clicked on their ad and were redirected to a page tagged with conversion tracking. However, they do not receive any information that would allow users to be personally identified. If you do not want to participate in tracking, you can block this use by disabling the Google conversion tracking cookie in your internet browser under user settings. You will then not be included in the conversion tracking statistics. We use Google Ads based on our legitimate interest in targeted advertising according to Art. 6 para. 1 lit. f GDPR. In the course of using Google Ads, personal data may also be transmitted to the servers of Google LLC in the USA.

In the event of the transfer of personal data to Google LLC, based in the USA, Google LLC has certified itself under the US-European data protection agreement "Privacy Shield," which ensures compliance with the data protection level applicable in the EU. A current certificate can be viewed here: https://www.privacyshield.gov/list

At the following internet address, you can find more information about Google's privacy policies: https://www.google.de/policies/privacy/

You can permanently disable cookies for ad preferences by preventing them through a corresponding setting in your browser software or by downloading and installing the browser plug-in available at the following link:
https://www.google.com/settings/ads/plugin?hl=de

Please note that certain functions of this website may not be available or may only be available to a limited extent if you have disabled the use of cookies.

10) Web analytics services

Google (Universal) Analytics

Google Universal Analytics with demographic features
This website uses Google Analytics, a web analytics service from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). Google Analytics uses so-called "cookies", text files that are stored on your computer and allow an analysis of your use of the website. The information generated by the cookie about your use of this website (including the shortened IP address) is usually transmitted to a Google server and stored there; this may also involve transmission to the servers of Google LLC in the USA.
This website uses Google Analytics exclusively with the "_anonymizeIp()" extension, which ensures anonymization of the IP address by truncation and excludes direct personal identification. Through the extension, your IP address is truncated by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area beforehand. Only in exceptional cases is the full IP address transmitted to a server of Google LLC in the USA and truncated there. In these exceptional cases, this processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes.
On our behalf, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide us with other services related to website and internet usage. The IP address transmitted by your browser within the scope of Google Analytics will not be merged with other data from Google.
You can prevent the storage of cookies by adjusting the settings of your browser software accordingly; however, we point out that in this case you may not be able to use all functions of this website fully. Furthermore, you can prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google as well as the processing of this data by Google by downloading and installing the browser plugin available at the following link:
https://tools.google.com/dlpage/gaoptout?hl=de
Alternatively to the browser plugin or within browsers on mobile devices, please click on the following link to set an opt-out cookie that will prevent data collection by Google Analytics on this website in the future (this opt-out cookie only works in this browser and only for this domain; if you delete your cookies in this browser, you must click this link again): Deactivate Google Analytics
In the event of the transfer of personal data to Google LLC, based in the USA, Google LLC has certified itself under the US-European data protection agreement "Privacy Shield," which ensures compliance with the data protection level applicable in the EU. A current certificate can be viewed here: https://www.privacyshield.gov/list
This website also uses Google Analytics for cross-device analysis of visitor flows, which is carried out via a User ID. When a page is accessed for the first time, the user is assigned a unique, permanent, and anonymized ID that is set across devices. This makes it possible to assign interaction data from different devices and from different sessions to a single user. The User ID contains no personal data and does not transmit any such data to Google.
The data collection and storage via the User-ID can be objected to at any time with effect for the future. For this, you must deactivate Google Analytics on all systems you use, for example in another browser or on your mobile device.
This website also uses the “demographic features” function of Google Analytics. This allows reports to be created that contain statements about demographic data such as age, gender, and interests of the site visitors. These data come from interest-based advertising by Google, the Google Display Network, as well as visitor data from third-party providers. You can disable this function at any time via the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as shown immediately.
You can deactivate this using a browser plugin from Google (https://tools.google.com/dlpage/gaoptout?hl=de). Alternatively to the browser plugin or within browsers on mobile devices, please click on the following link to set an opt-out cookie that will prevent data collection by Google Analytics on this website in the future (this opt-out cookie only works in this browser and only for this domain; if you delete your cookies in this browser, you must click this link again): Deactivate Google Analytics
Further information on Google (Universal) Analytics can be found here: https://support.google.com/analytics/answer/2838718?hl=de&ref_topic=6010376
Further information on Google (Universal) Analytics can be found here: https://support.google.com/analytics/answer/2838718?hl=de&ref_topic=6010376

11) Retargeting/ Remarketing/ Referral advertising

Facebook Custom Audience via the Pixel method
This website uses the “Facebook Pixel” of Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA (“Facebook”). In the event of granting explicit consent, this can track the behavior of users after they have seen or clicked on a Facebook advertisement. This procedure serves to evaluate the effectiveness of Facebook advertisements for statistical and market research purposes and can help optimize future advertising measures.
The data collected is anonymous to us, so it does not allow any conclusions about the identity of the users. However, the data is stored and processed by Facebook, so a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes in accordance with the Facebook Data Use Policy (https://www.facebook.com/about/privacy/). You can enable Facebook and its partners to display advertisements on and off Facebook. Furthermore, a cookie may be stored on your computer for these purposes. These processing operations are carried out exclusively upon granting explicit consent in accordance with Art. 6 para. 1 lit. a GDPR.
Consent to the use of the Facebook Pixel may only be given by users who are older than 13 years. If you are younger, we ask you to seek permission from your legal guardians.
Facebook Inc., based in the USA, is certified under the US-European data protection agreement "Privacy Shield," which ensures compliance with the data protection level applicable in the EU.
To disable the use of cookies on your computer, you can set your internet browser so that no cookies can be stored on your computer in the future or delete cookies already stored. However, disabling all cookies may result in some functions on our websites no longer being executable. You can also disable the use of cookies by third parties such as Facebook on the following website of the Digital Advertising Alliance: https://www.aboutads.info/choices/

Google Ads Remarketing
Our website uses the functions of Google Ads Remarketing; with this, we advertise this website in Google search results as well as on third-party websites. The provider is Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). For this purpose, Google sets a cookie in the browser of your device, which automatically enables interest-based advertising using a pseudonymous cookie ID and based on the pages you have visited. The processing is based on our legitimate interest in the optimal marketing of our website according to Art. 6 para. 1 lit. f GDPR.
Any further data processing only takes place if you have agreed to Google linking your internet and app browser history with your Google account and using information from your Google account to personalize ads you view on the web. If you are logged into Google during your visit to our website, Google uses your data together with Google Analytics data to create and define audience lists for cross-device remarketing. For this purpose, your personal data is temporarily linked by Google with Google Analytics data to form audiences. As part of the use of Google Ads Remarketing, personal data may also be transmitted to the servers of Google LLC in the USA.
You can permanently deactivate the setting of cookies for advertising preferences by downloading and installing the browser plug-in available at the following link: https://www.google.com/settings/ads/onweb/
Alternatively, you can inform yourself about the setting of cookies at the Digital Advertising Alliance at the internet address www.aboutads.info and make settings accordingly. Finally, you can configure your browser so that you are informed about the setting of cookies and decide individually on their acceptance or exclude the acceptance of cookies for certain cases or in general. If cookies are not accepted, the functionality of our website may be limited.
In the event of the transfer of personal data to Google LLC, based in the USA, Google LLC has certified itself under the US-European data protection agreement "Privacy Shield," which ensures compliance with the data protection level applicable in the EU. A current certificate can be viewed here: https://www.privacyshield.gov/list
Further information and the privacy policies regarding advertising and Google can be viewed here:
https://www.google.com/policies/technologies/ads/

12) Tools and Miscellaneous

Google Web Fonts

This site uses so-called web fonts provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google") for the uniform display of fonts. When a page is called up, your browser loads the required web fonts into its browser cache to display texts and fonts correctly.

For this purpose, the browser you use must connect to Google's servers, which may also result in the transfer of personal data to the servers of Google LLC in the USA. This allows Google to learn that our website was accessed via your IP address. The use of Google Web Fonts is in the interest of a uniform and appealing presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. If your browser does not support web fonts, a standard font from your computer will be used.

In the event of the transfer of personal data to Google LLC, based in the USA, Google LLC has certified itself under the US-European data protection agreement "Privacy Shield," which ensures compliance with the data protection level applicable in the EU. A current certificate can be viewed here: https://www.privacyshield.gov/list

Further information about Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google's privacy policy: https://www.google.com/policies/privacy/

13) Rights of the Data Subject

13.1 The applicable data protection law grants you comprehensive data subject rights (information and intervention rights) vis-à-vis the controller regarding the processing of your personal data, about which we inform you below:

  • Right of access pursuant to Art. 15 GDPR: You have, in particular, the right to access your personal data processed by us, the purposes of processing, the categories of personal data processed, the recipients or categories of recipients to whom your data have been or will be disclosed, the planned storage duration or the criteria for determining the storage duration, the existence of a right to rectification, deletion, restriction of processing, objection to processing, complaint to a supervisory authority, the origin of your data if not collected by us from you, the existence of automated decision-making including profiling and, if applicable, meaningful information about the involved logic and the scope and intended effects of such processing concerning you, as well as your right to information about the guarantees pursuant to Art. 46 GDPR when forwarding your data to third countries;
  • Right to rectification pursuant to Art. 16 GDPR: You have the right to immediate correction of incorrect data concerning you and/or completion of your incomplete data stored with us;
  • Right to deletion pursuant to Art. 17 GDPR: You have the right to request the deletion of your personal data if the conditions of Art. 17 para. 1 GDPR are met. However, this right does not exist in particular if the processing is necessary for exercising the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the assertion, exercise, or defense of legal claims;
  • Right to restriction of processing pursuant to Art. 18 GDPR: You have the right to request the restriction of the processing of your personal data while the accuracy of your disputed data is being verified, if you refuse the deletion of your data due to unlawful data processing and instead request the restriction of the processing of your data, if you need your data to assert, exercise, or defend legal claims after we no longer need this data for the purpose, or if you have objected for reasons of your particular situation as long as it is not yet determined whether our legitimate reasons prevail;
  • Right to information pursuant to Art. 19 GDPR: If you have asserted the right to rectification, deletion, or restriction of processing against the controller, the controller is obliged to inform all recipients to whom the personal data concerning you have been disclosed of this rectification or deletion of the data or restriction of processing, unless this proves impossible or involves a disproportionate effort. You have the right to be informed about these recipients.
  • Right to data portability under Art. 20 GDPR: You have the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format or to request the transfer to another controller, insofar as this is technically feasible;
  • Right to withdraw given consents under Art. 7 para. 3 GDPR: You have the right to withdraw any consent given to the processing of data at any time with effect for the future. In the event of withdrawal, we will delete the affected data immediately, provided that further processing cannot be based on a legal basis for processing without consent. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal;
  • Right to lodge a complaint under Art. 77 GDPR: If you believe that the processing of your personal data violates the GDPR, you have - without prejudice to any other administrative or judicial remedy - the right to lodge a complaint with a supervisory authority, especially in the member state of your residence, workplace, or the place of the alleged infringement.

13.2 RIGHT TO OBJECT

IF WE PROCESS YOUR PERSONAL DATA BASED ON OUR OVERRIDING LEGITIMATE INTERESTS AS PART OF A BALANCE OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION WITH EFFECT FOR THE FUTURE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED. HOWEVER, FURTHER PROCESSING IS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS, AND FREEDOMS, OR IF THE PROCESSING SERVES THE ASSERTION, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.

IF YOUR PERSONAL DATA IS PROCESSED BY US FOR DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING PURPOSES. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.

14) Duration of storage of personal data

The duration of the storage of personal data is determined by the respective statutory retention period (e.g., commercial and tax law retention periods). After the period expires, the corresponding data will be routinely deleted, provided they are no longer required for contract fulfillment or contract initiation and/or we no longer have a legitimate interest in further storage.